Malicious code in @years19/n8n-nodes-utils-helper-v (npm)
The npm package @years19/n8n-nodes-utils-helper-v contained malicious code that executes on both installation and import, launching a DDoS attack and exfiltrating host identity data.
- Disclosed
- Last updated
- Blast radius
- Any system installing or requiring the malicious package becomes a participant in a DDoS attack and leaks host identity information.
- Ecosystems
- Attack vectors
- Affected entities
- @years19/n8n-nodes-utils-helper-v
The npm package @years19/n8n-nodes-utils-helper-v was found to contain malicious code that executes via a postinstall hook and through the main entry point. The payload writes a Python UDP/TCP flood script to /tmp/attack.py and launches it, directing approximately 650 threads at IP 103.118.252.21 on ports 80 and 443 for 600 seconds.\n\nIn parallel, the malicious code executes system reconnaissance commands (id and hostname), collects process and load average indicators, base64-encodes the results, and exfiltrates this data via HTTPS to https://jasabersama.id/portfolio-data.php with a hardcoded query parameter. The code disables certificate validation during exfiltration.\n\nAny system that installs the package or imports it becomes an unwitting participant in an outbound DDoS attack while simultaneously leaking host identity information to an attacker-controlled endpoint. The incident was identified and credited to the OpenSSF malicious packages project.
Indicators of compromise
- Packages
- @years19/n8n-nodes-utils-helper-v
- Domains
- jasabersama.id
- IPs
- 103.118.252.21
Remediation
- Immediately uninstall @years19/n8n-nodes-utils-helper-v from all systems
- Audit npm install logs to identify all systems that may have installed this package
- Terminate any running Python processes spawned by the malicious payload
- Review network logs for outbound DDoS traffic to 103.118.252.21 on ports 80/443
- Check for exfiltrated host identity data sent to jasabersama.id
- Verify the integrity of any systems that installed or required this package
- Use npm audit to identify if this package was a transitive dependency
- Consider blocking the attacker IP and domain at network perimeter
Sources
- GitHub Advisory GHSA-mgx8-6pv9-w46r · GitHub Advisory Database
Cite this entry
"Malicious code in @years19/n8n-nodes-utils-helper-v (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years19-n8n-nodes-utils-helper-v-npm-qawku5
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in bolt-delivery-menu-app
The npm package bolt-delivery-menu-app contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in bucket-protocol-sdk-v2
Malware discovered in the npm package bucket-protocol-sdk-v2. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in sui-gql-core
Malware was discovered in the npm package sui-gql-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in sui-move-rpc
Malware was discovered in the npm package sui-move-rpc, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package