Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @years19/n8n-nodes-utils-helper-v (npm)

The npm package @years19/n8n-nodes-utils-helper-v contained malicious code that executes on both installation and import, launching a DDoS attack and exfiltrating host identity data.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any system installing or requiring the malicious package becomes a participant in a DDoS attack and leaks host identity information.
Ecosystems
Attack vectors
Affected entities
  • @years19/n8n-nodes-utils-helper-v

The npm package @years19/n8n-nodes-utils-helper-v was found to contain malicious code that executes via a postinstall hook and through the main entry point. The payload writes a Python UDP/TCP flood script to /tmp/attack.py and launches it, directing approximately 650 threads at IP 103.118.252.21 on ports 80 and 443 for 600 seconds.\n\nIn parallel, the malicious code executes system reconnaissance commands (id and hostname), collects process and load average indicators, base64-encodes the results, and exfiltrates this data via HTTPS to https://jasabersama.id/portfolio-data.php with a hardcoded query parameter. The code disables certificate validation during exfiltration.\n\nAny system that installs the package or imports it becomes an unwitting participant in an outbound DDoS attack while simultaneously leaking host identity information to an attacker-controlled endpoint. The incident was identified and credited to the OpenSSF malicious packages project.

Indicators of compromise

Packages
  • @years19/n8n-nodes-utils-helper-v
Domains
  • jasabersama.id
IPs
  • 103.118.252.21

Remediation

  • Immediately uninstall @years19/n8n-nodes-utils-helper-v from all systems
  • Audit npm install logs to identify all systems that may have installed this package
  • Terminate any running Python processes spawned by the malicious payload
  • Review network logs for outbound DDoS traffic to 103.118.252.21 on ports 80/443
  • Check for exfiltrated host identity data sent to jasabersama.id
  • Verify the integrity of any systems that installed or required this package
  • Use npm audit to identify if this package was a transitive dependency
  • Consider blocking the attacker IP and domain at network perimeter

Sources

  1. GitHub Advisory GHSA-mgx8-6pv9-w46r · GitHub Advisory Database

Cite this entry

"Malicious code in @years19/n8n-nodes-utils-helper-v (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years19-n8n-nodes-utils-helper-v-npm-qawku5

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    Malware in bolt-delivery-menu-app

    The npm package bolt-delivery-menu-app contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2. activecritical

    Malware in bucket-protocol-sdk-v2

    Malware discovered in the npm package bucket-protocol-sdk-v2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  3. containedcritical

    Malware in sui-gql-core

    Malware was discovered in the npm package sui-gql-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  4. containedcritical

    Malware in sui-move-rpc

    Malware was discovered in the npm package sui-move-rpc, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package