{"id":"MAL-2026-13871","summary":"Malicious code in @years17/n8n-nodes-utils-helper-b (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (55dc5bbe5a3b2dfb5bf97920ee68027b585bc2b21f4388e88a25986318754397)\nThe package runs credential-harvesting recon both from its postinstall script and from its main entry (executed at require time). The postinstall collects `id`/`hostname`, docker socket state, `sudo -n -l`, `docker ps`, listings of `/home/ubuntu` and `/root`, `~/.ssh/authorized_keys`, and scrapes `env` for variables matching `docker|n8n|secret|token|key|pass`. The main module additionally reads `~/.kube/config`, `~/.ssh/authorized_keys`, and `~/.config/gcloud/application_default_credentials.json`, plus SSH directory listing and crontab. In both paths the aggregate output is base64-encoded and sent as the `c=` query-string parameter to `https://jasabersama.id/portfolio-data.php?k=S7k9xQ2mZj` via `https.request` with `rejectUnauthorized:false` (TLS verification disabled). The package additionally ships an n8n node (`nodes/PwnNode.node.js`) whose `execute()` runs `id; hostname; uname -a; ls -la /home; ls -la /` via `child_process.execSync` and returns the output as `{ pwned: true, result: out }`, providing arbitrary host reconnaissance inside the installer's n8n runtime.\n","modified":"2026-08-12T13:00:18.614110481Z","published":"2026-08-12T12:38:38Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-017559","import_time":"2026-08-12T12:51:50.228104825Z","modified_time":"2026-08-12T12:38:38Z","sha256":"55dc5bbe5a3b2dfb5bf97920ee68027b585bc2b21f4388e88a25986318754397","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@years17/n8n-nodes-utils-helper-b/v/1.0.0"}],"affected":[{"package":{"name":"@years17/n8n-nodes-utils-helper-b","ecosystem":"npm","purl":"pkg:npm/%40years17/n8n-nodes-utils-helper-b"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"8d1142f9367c8d308af0c4d75d4b9a5bd09bd10366b2b9c8e08c09952fcb95840134fd","path":"callback.js","sha256":"669e2b699905aaea1f583b077ba97eac1ffc35d7b47a70425caed7ccdd4a9d98"},{"path":"index.js","sha256":"65c43ef8e35925d41e4368dd3ac9653fa898a55980afec20b21195f0167d9208","tlsh":"cd2154f6337c9a300bb5c5575d5fa256e4db810214b6b5cce0cc4d452fcb98c41129f4"},{"sha256":"b4b05aecc01697e3bb67ad3be71d575674cc2ee0cbd81e01985289242f4d4059","tlsh":"fe111ef7adb6e2600092b4d75b07a1022822c3172725bc79ba8c46534f4894ca7b1ef8","path":"nodes/PwnNode.node.js"}],"package_integrity":[{"filename":"n8n-nodes-utils-helper-b-1.0.0.tgz","hashes":{"sha1":"aaebce20f950fae962dbc542495d5f6e1aa8e824","sha512_sri":"sha512-iveDokxEDQOaqD6hxeQ11arZMYRRX2u54rlwbozr1VVig5Jc8fhUzKgx4GN2gx5uI19XKbPgEScPJJ6qFBMU3g=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@years17/n8n-nodes-utils-helper-b/MAL-2026-13871.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}