Malicious code in @years19/n8n-nodes-utils-helper-q (npm)
The npm package @years19/n8n-nodes-utils-helper-q@1.0.0 contained malicious code that executed on install and on require(), downloading DDoS tools and turning infected machines into attack nodes while exfiltrating host identity information.
- Disclosed
- Last updated
- Blast radius
- Any developer or system that installed @years19/n8n-nodes-utils-helper-q@1.0.0 from npm
- Ecosystems
- Attack vectors
- Affected entities
- @years19/n8n-nodes-utils-helper-q · 1.0.0
The npm package @years19/n8n-nodes-utils-helper-q version 1.0.0 shipped with malicious code in two identical top-level scripts (callback.js and index.js). The package.json declared "main":"index.js" and "postinstall":"node callback.js", ensuring the payload executed both during npm install and on any require()/import of the package.\n\nUpon execution, the scripts downloaded multiple tarballs (mhddos, pyroxy, impacket, multidict) from jasabersama.id over HTTPS with certificate verification disabled (rejectUnauthorized:false), extracted them to /tmp, and spawned python3 start.py in the background to launch UDP/TCP/GET flood traffic against 103.118.252.21, converting the installer's machine into a DDoS attack node.\n\nIn parallel, the scripts executed id and hostname commands, base64-encoded the output, and sent it via HTTPS GET to jasabersama.id/portfolio-data.php to exfiltrate installer host identity to an attacker-controlled endpoint.\n\nThis represents a canonical install-time RCE/dropper attack with multiple auto-execution paths, disabled TLS validation, and execution of opaque archives from an unrelated non-publisher host.
Indicators of compromise
- Packages
- @years19/n8n-nodes-utils-helper-q
- Domains
- jasabersama.id
- IPs
- 103.118.252.21
Remediation
- Immediately uninstall @years19/n8n-nodes-utils-helper-q@1.0.0 from all systems
- Audit npm install logs to identify all machines that installed this package
- Inspect affected systems for DDoS tools (mhddos, pyroxy, impacket, multidict) in /tmp and running python3 processes
- Monitor network traffic from affected systems for outbound DDoS activity to 103.118.252.21
- Review firewall and network logs for suspicious outbound connections to jasabersama.id
- Regenerate credentials and SSH keys on affected systems
- Consider full system reimaging for critical infrastructure that installed this package
Sources
- GitHub Advisory GHSA-952v-gx2v-q8fx · GitHub Advisory Database
Cite this entry
"Malicious code in @years19/n8n-nodes-utils-helper-q (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years19-n8n-nodes-utils-helper-q-npm-1nxvci
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in @junofficial/baileys
The npm package @junofficial/baileys contained malware that fully compromised any system with the package installed or running. The malicious package has been identified and removed from distribution.
npmCompromised package - containedcritical
Malware in a.poltoradnev-package-a
The npm package a.poltoradnev-package-a contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in @zynkit/probe
Malware discovered in the npm package @zynkit/probe. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in awesome-ts-jest
Malware was discovered in the npm package awesome-ts-jest. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package