Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @years19/n8n-nodes-utils-helper-n (npm)

The npm package @years19/n8n-nodes-utils-helper-n contained malicious code that executes on install and on require(), downloading DDoS tools and weaponizing the host as a participant in attacks against 103.118.252.21, while exfiltrating system identity data.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any system installing @years19/n8n-nodes-utils-helper-n becomes a DDoS participant; data exfiltration of system identity information.
Ecosystems
Attack vectors
Affected entities
  • @years19/n8n-nodes-utils-helper-nMalicious npm package masquerading as n8n community-node utility

The package @years19/n8n-nodes-utils-helper-n was published to npm with a postinstall script that executes malicious code. The package.json declares a postinstall hook running node callback.js, and the main entry point (index.js) is byte-identical to callback.js, ensuring the payload executes both during npm install and on any subsequent require() of the package.\n\nThe payload fetches four tarballs (mhddos, pyroxy-full, impacket, multidict) from https://jasabersama.id/assets/cache/.theme-backup/dl/ over HTTPS with TLS verification disabled, extracts them into /tmp and the user's site-packages directory, and launches three background Python3 processes running mhddos in UDP, TCP, and GET attack modes against the IP address 103.118.252.21. This weaponizes the installer's host as a DDoS participant.\n\nThe malicious code also collects system information via id and hostname commands, base64-encodes the output, and sends it as a query parameter to https://jasabersama.id/portfolio-data.php with TLS verification disabled, exfiltrating system identity data.\n\nThe package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2026-13897.

Indicators of compromise

Domains
  • jasabersama.id
IPs
  • 103.118.252.21

Remediation

  • Immediately uninstall @years19/n8n-nodes-utils-helper-n from all systems
  • Audit npm install logs and package-lock.json to identify all systems that installed this package
  • Terminate any background Python3 processes running mhddos or related DDoS tools
  • Review firewall and network logs for outbound connections to 103.118.252.21 and jasabersama.id
  • Regenerate credentials and review system access logs on affected hosts
  • Monitor affected systems for signs of compromise or data exfiltration
  • Use npm audit to check for other malicious packages in your dependency tree

Sources

  1. GitHub Advisory GHSA-jj4r-6865-f6xp · GitHub Advisory Database

Cite this entry

"Malicious code in @years19/n8n-nodes-utils-helper-n (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years19-n8n-nodes-utils-helper-n-npm-gk8b4c

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    Malware in @ai-vertical/ai-agent

    Malware was discovered in the npm package @ai-vertical/ai-agent. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  2. containedcritical

    Malicious code in checkout-desktop-total (npm)

    The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.

    npmCompromised package
  3. containedcritical

    Malicious code in pfp-forms-sme-loan (npm)

    The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.

    npmCompromised packageMalicious commit
  4. resolvedcritical

    Malicious code in epic-sso (npm)

    The npm package epic-sso was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package