Malicious code in @years19/n8n-nodes-utils-helper-r (npm)
The npm package @years19/n8n-nodes-utils-helper-r contained malicious code that executed during installation and on require(), downloading DDoS tools and launching attacks against a hardcoded target while exfiltrating system information.
- Disclosed
- Last updated
- Blast radius
- Any developer or system that installed @years19/n8n-nodes-utils-helper-r via npm
- Ecosystems
- Attack vectors
- Affected entities
- @years19/n8n-nodes-utils-helper-rMalicious npm package
The npm package @years19/n8n-nodes-utils-helper-r was published with embedded malicious code designed to execute at multiple trigger points. The package's postinstall script and main entry point (index.js) were byte-identical, ensuring the payload executed both during npm install and when the module was required, even when postinstall scripts were disabled via --ignore-scripts.\n\nUpon execution, the malicious code fetched multiple tarballs (mhddos, PyRoxy, impacket) from https://jasabersama.id/assets/cache/.theme-backup/dl/ with TLS certificate validation disabled, extracted them into /tmp and the user's Python site-packages directory, and spawned long-running Python flood processes targeting 103.118.252.21:80 via UDP. In parallel, the code collected system information including user ID, hostname, Python version, installed dependencies, and attack logs, base64-encoded the data, and exfiltrated it to https://jasabersama.id/portfolio-data.php.\n\nThe attack was identified by the OpenSSF's malicious-packages project and attributed to Amazon Inspector detection. The package represents a supply chain compromise delivering DDoS malware and system reconnaissance capabilities to any system that installed it.
Indicators of compromise
- Packages
- @years19/n8n-nodes-utils-helper-r
- Domains
- jasabersama.id
- IPs
- 103.118.252.21
Remediation
- Immediately uninstall @years19/n8n-nodes-utils-helper-r from all systems
- Check for and remove any Python packages installed in site-packages from the malicious tarballs (mhddos, PyRoxy, impacket)
- Terminate any running Python processes spawned by the malicious code
- Audit system logs and network traffic for connections to 103.118.252.21:80 and jasabersama.id
- Review npm audit logs and package.json for any other suspicious dependencies
- Consider full system remediation if the package was installed on production systems
Sources
- GitHub Advisory GHSA-x5j4-mr7j-5f4q · GitHub Advisory Database
Cite this entry
"Malicious code in @years19/n8n-nodes-utils-helper-r (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years19-n8n-nodes-utils-helper-r-npm-1ezg3l
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in banana-stand
The npm package banana-stand contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @siwatfa/yorn
Malware was discovered in the npm package @siwatfa/yorn. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - resolvedcritical
Malicious code in epic-common-node (npm)
The npm package epic-common-node was found to contain malicious code. The package has been identified and reported through GitHub Security Advisory GHSA-m36g-mhjr-ww2c.
npmCompromised package - activecritical
Malware in rendezvous-js
The npm package rendezvous-js contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package