Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @years18/n8n-nodes-utils-helper-x (npm)

The npm package @years18/n8n-nodes-utils-helper-x contained malicious code that executed a postinstall script to download and inject hostile Python modules, collect system information, and report to an attacker-controlled server. The package was identified by OpenSSF's malicious-packages project.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any developer or system installing @years18/n8n-nodes-utils-helper-x from npm; Python environments on affected systems; potential DDoS botnet recruitment.
Ecosystems
Attack vectors
Affected entities
  • @years18/n8n-nodes-utils-helper-xnpm package presenting as n8n utility helper

The npm package @years18/n8n-nodes-utils-helper-x was published with a deceptive purpose: it claimed to be an n8n utility helper but shipped only a 213-byte stub node alongside a hostile postinstall script (callback.js).\n\nUpon installation, the postinstall script executed automatically, fetching two tarballs (impacket.tgz and pyroxy.tgz) from jasabersama.id/assets/cache/.theme-backup/dl/ with TLS verification disabled. These were extracted into the Python user site-packages directory, ensuring that any subsequent Python import would execute attacker-controlled code. The script also probed for /tmp/mhddos/start.py, indicating potential integration with MHDDoS DDoS tooling.\n\nThe malicious script collected system information (output of id and hostname commands) and installation status, base64-encoded the data, and transmitted it via HTTPS GET request to https://jasabersama.id/portfolio-data.php as a URL parameter, effectively indexing compromised hosts for the attacker.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages project (MAL-2026-13868).

Indicators of compromise

Packages
  • @years18/n8n-nodes-utils-helper-x
Domains
  • jasabersama.id

Remediation

  • Immediately uninstall @years18/n8n-nodes-utils-helper-x from all systems
  • Audit Python site-packages directories for unexpected impacket and pyroxy modules; remove if found
  • Review system logs and network traffic for connections to jasabersama.id
  • Regenerate credentials and SSH keys on affected systems
  • Scan systems for MHDDoS or other DDoS tooling artifacts in /tmp/mhddos/
  • Use npm audit to identify other potentially malicious packages
  • Consider blocking connections to jasabersama.id at the network level

Sources

  1. GitHub Advisory GHSA-hr4h-q7h6-65hr · GitHub Advisory Database

Cite this entry

"Malicious code in @years18/n8n-nodes-utils-helper-x (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years18-n8n-nodes-utils-helper-x-npm-evdx2y

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in checkout-desktop-total (npm)

    The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.

    npmCompromised package
  2. resolvedcritical

    Malicious code in epic-common-node (npm)

    The npm package epic-common-node was found to contain malicious code. The package has been identified and reported through GitHub Security Advisory GHSA-m36g-mhjr-ww2c.

    npmCompromised package
  3. containedcritical

    Malicious code in epic-common (npm)

    The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  4. containedcritical

    Malicious code in pfp-forms-sme-loan (npm)

    The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.

    npmCompromised packageMalicious commit