Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @years19/n8n-nodes-utils-helper-e (npm)

The npm package @years19/n8n-nodes-utils-helper-e contains malicious code that executes a postinstall script to download and extract offensive Python libraries, collect host identity information, and exfiltrate data to a remote server. The package falsely presents itself as an n8n community utility node.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any developer or system installing @years19/n8n-nodes-utils-helper-e from npm; systems running affected installations exposed to remote code execution and data exfiltration.
Ecosystems
Attack vectors
Affected entities
  • @years19/n8n-nodes-utils-helper-eMalicious npm package masquerading as n8n community utility node

The npm package @years19/n8n-nodes-utils-helper-e was published with malicious intent. While the package presents itself as an n8n community utility node, the actual node file (nodes/PwnNode.node.js) is a non-functional 213-byte stub.

The malicious behavior is embedded in the postinstall lifecycle script, which executes automatically upon package installation. The script collects host identity information via the id and hostname commands, then downloads a compressed archive (multidict.tgz) from https://jasabersama.id/assets/cache/.theme-backup/dl/ with TLS verification disabled. The archive is extracted into the user's Python site-packages directory.

The postinstall script probes for and stages offensive Python libraries including mhddos, PyRoxy, and impacket, then executes /tmp/mhddos/start.py. Captured host identity and probe output are base64-encoded and exfiltrated to https://jasabersama.id/portfolio-data.php as query parameters, again with TLS verification disabled.

The package publisher has no legitimate association with jasabersama.id or n8n. This incident was identified and reported by the OpenSSF malicious packages project.

Indicators of compromise

Packages
  • @years19/n8n-nodes-utils-helper-e
Domains
  • jasabersama.id

Remediation

  • Immediately uninstall @years19/n8n-nodes-utils-helper-e from all systems
  • Audit npm package.json and lock files for any installations of this package
  • Review system logs and process execution history on any machine where this package was installed
  • Inspect Python site-packages directories for unexpected mhddos, PyRoxy, or impacket installations
  • Monitor for suspicious outbound connections to jasabersama.id
  • Regenerate any credentials or sensitive data that may have been exposed on affected systems
  • Use npm audit to identify and remediate any other malicious or compromised dependencies

Sources

  1. GitHub Advisory GHSA-xh5q-2rp9-9prh · GitHub Advisory Database

Cite this entry

"Malicious code in @years19/n8n-nodes-utils-helper-e (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years19-n8n-nodes-utils-helper-e-npm-sfdy1j

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in epic-common-node (npm)

    The npm package epic-common-node was found to contain malicious code. The package has been identified and reported through GitHub Security Advisory GHSA-m36g-mhjr-ww2c.

    npmCompromised package
  2. containedcritical

    Malicious code in epic-common (npm)

    The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  3. containedcritical

    Malware in leb128x

    The npm package leb128x was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  4. containedcritical

    Malicious code in checkout-desktop-total (npm)

    The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.

    npmCompromised package