Malicious code in @years18/n8n-nodes-utils-helper-d (npm)
The npm package @years18/n8n-nodes-utils-helper-d contained malicious code that executed on install via postinstall hook, downloading and executing a DDoS tool, exfiltrating system information, and performing internal network reconnaissance.
- Disclosed
- Last updated
- Blast radius
- Any developer or system that installed @years18/n8n-nodes-utils-helper-d from npm
- Ecosystems
- Attack vectors
- Affected entities
- @years18/n8n-nodes-utils-helper-dMalicious npm package masquerading as n8n community node
The npm package @years18/n8n-nodes-utils-helper-d was published as a purported n8n community node but contained malicious code designed to compromise the installer's system. The package's node file (nodes/PwnNode.node.js) was a stub; the actual malicious behavior was implemented in callback.js, which was automatically executed via the postinstall lifecycle hook.\n\nOn installation, callback.js performed three attacker-controlled actions: (1) it downloaded https://jasabersama.id/assets/cache/.theme-backup/dl/mhddos.tgz with certificate validation disabled, extracted it, installed its Python dependencies, and executed start.py—providing unattended remote code execution of a mutable third-party archive associated with the mhddos DDoS tool family; (2) it executed system reconnaissance commands (id, hostname) and probed an internal TCP endpoint, then base64-encoded and exfiltrated the results to https://jasabersama.id/portfolio-data.php, leaking installer identity and network topology; (3) it executed bash commands against a hardcoded RFC1918 address (10.131.106.93:8888) with a source comment referencing Sliver, an offensive C2 framework, and reported reachability back—consistent with lateral-movement staging.\n\nThe same payload was duplicated in index.js to ensure execution on module require. The package was identified via Amazon Inspector and published to GitHub advisories."
Indicators of compromise
- Packages
- @years18/n8n-nodes-utils-helper-d
- Domains
- jasabersama.id
- IPs
- 10.131.106.93
Remediation
- Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials.
Sources
- GitHub Advisory GHSA-x25g-8xwh-r682 · GitHub Advisory Database
Cite this entry
"Malicious code in @years18/n8n-nodes-utils-helper-d (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years18-n8n-nodes-utils-helper-d-npm-1uyvei
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in envfile-sync-cli
Malware was discovered in the npm package envfile-sync-cli, providing full system compromise to any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @zizie071/libsignal-node
The npm package @zizie071/libsignal-node contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in sui-move-rpc
Malware was discovered in the npm package sui-move-rpc, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in @siwatfa/yorn
Malware was discovered in the npm package @siwatfa/yorn. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package