{"id":"MAL-2026-13858","summary":"Malicious code in @years18/n8n-nodes-utils-helper-n (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f747eb82d36d203eb7d0e49df70c41f696f8909284c48a4a8d6a7e785e1b5f98)\nThe package's postinstall script (callback.js) and its declared main (index.js) both fetch two tarballs from https://jasabersama.id/assets/cache/.theme-backup/dl/ (mhddos.tgz and pyroxy.tgz) over an HTTPS connection with certificate verification disabled (rejectUnauthorized:false), extract mhddos.tgz to /tmp/mhddos and pyroxy.tgz into the installer's Python site-packages, force-install a set of unpinned Python packages using `python3 -m pip install --break-system-packages` (pysocks, cloudscraper, dnspython, psutil, icmplib, pyasn1, yarl, requests_toolbelt, certifi), and then execute `python3 start.py` from the extracted MHDDoS directory. Separately, the same script collects the output of `id` and `hostname`, base64-encodes the result, and issues an HTTPS GET to jasabersama.id/portfolio-data.php with a hardcoded key parameter, providing the operator of that host a per-install beacon carrying installer identity. Because the dropper logic is duplicated in index.js, any consumer that does `require('@years18/n8n-nodes-utils-helper-n')` re-triggers the fetch, extraction, pip install, DDoS launcher, and beacon in addition to the automatic postinstall execution. The advertised package name imitates the n8n community-node namespace; the shipped code has no relation to an n8n node.\n","modified":"2026-08-12T12:30:16.514131994Z","published":"2026-08-12T12:16:21Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017400","import_time":"2026-08-12T12:24:09.91560672Z","modified_time":"2026-08-12T12:16:21Z","sha256":"f747eb82d36d203eb7d0e49df70c41f696f8909284c48a4a8d6a7e785e1b5f98","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@years18/n8n-nodes-utils-helper-n/v/1.0.0"}],"affected":[{"package":{"name":"@years18/n8n-nodes-utils-helper-n","ecosystem":"npm","purl":"pkg:npm/%40years18/n8n-nodes-utils-helper-n"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"939b22deea396f3518d6d974069b37918201181f7ce418fdac8cf4ad161f7f6c","tlsh":"8f4198b61252a538403363586f2bdd66d66fb10784d8bac8f64d43730f129386d5b76c","path":"callback.js"},{"sha256":"939b22deea396f3518d6d974069b37918201181f7ce418fdac8cf4ad161f7f6c","tlsh":"8f4198b61252a538403363586f2bdd66d66fb10784d8bac8f64d43730f129386d5b76c","path":"index.js"}],"package_integrity":[{"hashes":{"sha1":"5a93b29f8b929a6e2fd73201c9639b3ee6994ccb","sha512_sri":"sha512-mcm+VuecMgxY3tCJXqlJq4/pZRNMwHOgvprrMjvWfr582JoSdc4fqEgvkNdatXCAa4LwFrsIgOX5HMZIPrqIAw=="},"filename":"n8n-nodes-utils-helper-n-1.0.0.tgz"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@years18/n8n-nodes-utils-helper-n/MAL-2026-13858.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}