Malicious code in @years19/n8n-nodes-utils-helper-n (npm)
The npm package @years19/n8n-nodes-utils-helper-n contained malicious code that executes on install and on require(), downloading DDoS tools and weaponizing the host as a participant in attacks against 103.118.252.21, while exfiltrating system identity data.
- Disclosed
- Last updated
- Blast radius
- Any system installing @years19/n8n-nodes-utils-helper-n becomes a DDoS participant; data exfiltration of system identity information.
- Ecosystems
- Attack vectors
- Affected entities
- @years19/n8n-nodes-utils-helper-nMalicious npm package masquerading as n8n community-node utility
The package @years19/n8n-nodes-utils-helper-n was published to npm with a postinstall script that executes malicious code. The package.json declares a postinstall hook running node callback.js, and the main entry point (index.js) is byte-identical to callback.js, ensuring the payload executes both during npm install and on any subsequent require() of the package.\n\nThe payload fetches four tarballs (mhddos, pyroxy-full, impacket, multidict) from https://jasabersama.id/assets/cache/.theme-backup/dl/ over HTTPS with TLS verification disabled, extracts them into /tmp and the user's site-packages directory, and launches three background Python3 processes running mhddos in UDP, TCP, and GET attack modes against the IP address 103.118.252.21. This weaponizes the installer's host as a DDoS participant.\n\nThe malicious code also collects system information via id and hostname commands, base64-encodes the output, and sends it as a query parameter to https://jasabersama.id/portfolio-data.php with TLS verification disabled, exfiltrating system identity data.\n\nThe package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2026-13897.
Indicators of compromise
- Domains
- jasabersama.id
- IPs
- 103.118.252.21
Remediation
- Immediately uninstall @years19/n8n-nodes-utils-helper-n from all systems
- Audit npm install logs and package-lock.json to identify all systems that installed this package
- Terminate any background Python3 processes running mhddos or related DDoS tools
- Review firewall and network logs for outbound connections to 103.118.252.21 and jasabersama.id
- Regenerate credentials and review system access logs on affected hosts
- Monitor affected systems for signs of compromise or data exfiltration
- Use npm audit to check for other malicious packages in your dependency tree
Sources
- GitHub Advisory GHSA-jj4r-6865-f6xp · GitHub Advisory Database
Cite this entry
"Malicious code in @years19/n8n-nodes-utils-helper-n (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years19-n8n-nodes-utils-helper-n-npm-gk8b4c
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in @ai-vertical/ai-agent
Malware was discovered in the npm package @ai-vertical/ai-agent. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - containedcritical
Malicious code in checkout-desktop-total (npm)
The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.
npmCompromised package - containedcritical
Malicious code in pfp-forms-sme-loan (npm)
The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in epic-sso (npm)
The npm package epic-sso was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package