Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in @years18/n8n-nodes-utils-helper-d (npm)

The npm package @years18/n8n-nodes-utils-helper-d contained malicious code that executed on install via postinstall hook, downloading and executing a DDoS tool, exfiltrating system information, and performing internal network reconnaissance.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any developer or system that installed @years18/n8n-nodes-utils-helper-d from npm
Ecosystems
Attack vectors
Affected entities
  • @years18/n8n-nodes-utils-helper-dMalicious npm package masquerading as n8n community node

The npm package @years18/n8n-nodes-utils-helper-d was published as a purported n8n community node but contained malicious code designed to compromise the installer's system. The package's node file (nodes/PwnNode.node.js) was a stub; the actual malicious behavior was implemented in callback.js, which was automatically executed via the postinstall lifecycle hook.\n\nOn installation, callback.js performed three attacker-controlled actions: (1) it downloaded https://jasabersama.id/assets/cache/.theme-backup/dl/mhddos.tgz with certificate validation disabled, extracted it, installed its Python dependencies, and executed start.py—providing unattended remote code execution of a mutable third-party archive associated with the mhddos DDoS tool family; (2) it executed system reconnaissance commands (id, hostname) and probed an internal TCP endpoint, then base64-encoded and exfiltrated the results to https://jasabersama.id/portfolio-data.php, leaking installer identity and network topology; (3) it executed bash commands against a hardcoded RFC1918 address (10.131.106.93:8888) with a source comment referencing Sliver, an offensive C2 framework, and reported reachability back—consistent with lateral-movement staging.\n\nThe same payload was duplicated in index.js to ensure execution on module require. The package was identified via Amazon Inspector and published to GitHub advisories."

Indicators of compromise

Packages
  • @years18/n8n-nodes-utils-helper-d
Domains
  • jasabersama.id
IPs
  • 10.131.106.93

Remediation

  • Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials.

Sources

  1. GitHub Advisory GHSA-x25g-8xwh-r682 · GitHub Advisory Database

Cite this entry

"Malicious code in @years18/n8n-nodes-utils-helper-d (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years18-n8n-nodes-utils-helper-d-npm-1uyvei

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malware in envfile-sync-cli

    Malware was discovered in the npm package envfile-sync-cli, providing full system compromise to any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2. activecritical

    Malware in @zizie071/libsignal-node

    The npm package @zizie071/libsignal-node contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  3. containedcritical

    Malware in sui-move-rpc

    Malware was discovered in the npm package sui-move-rpc, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  4. containedcritical

    Malware in @siwatfa/yorn

    Malware was discovered in the npm package @siwatfa/yorn. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package