Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @years19/n8n-nodes-utils-helper-y (npm)

The npm package @years19/n8n-nodes-utils-helper-y contained malicious code that executes on install and on every require, launching DDoS attacks and exfiltrating host identity information to a remote server.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any system installing or requiring @years19/n8n-nodes-utils-helper-y
Ecosystems
Attack vectors
Affected entities
  • @years19/n8n-nodes-utils-helper-yMalicious npm package masquerading as n8n community utility helper node

The package @years19/n8n-nodes-utils-helper-y was published to npm with malicious intent, disguised as a legitimate n8n community utility helper node. The package.json declared a postinstall hook and a main entry point, both containing identical malicious code.\n\nUpon installation or when the package is required, the malicious code executes in two stages: (1) it writes a Python script to /tmp/attack2.py and launches it via nohup, which floods the IP address 103.118.252.21 on ports 80 and 443 with UDP/TCP traffic using 2000 threads for 900 seconds; and (2) it collects host identity information including uid, hostname, and process/load data, base64-encodes it, and sends it over HTTPS GET to jasabersama.id/portfolio-data.php with TLS certificate verification disabled.\n\nBecause the malicious code is present in both the postinstall script and the top-level module code, it executes both during npm install and every time a consumer requires the package or n8n loads the node, creating persistent compromise.\n\nThe incident was identified and reported by the OpenSSF malicious-packages project.

Indicators of compromise

Packages
  • @years19/n8n-nodes-utils-helper-y
Domains
  • jasabersama.id
IPs
  • 103.118.252.21

Remediation

  • Immediately uninstall @years19/n8n-nodes-utils-helper-y from all systems
  • Audit npm install logs and process history for execution of callback.js and /tmp/attack2.py
  • Review network logs for outbound traffic to 103.118.252.21 (ports 80/443) and jasabersama.id
  • Check for any HTTPS GET requests to jasabersama.id/portfolio-data.php
  • Regenerate credentials and review access logs on affected systems
  • Block the malicious domains and IP addresses at the network perimeter
  • Use npm audit to identify any other malicious packages in your dependency tree

Sources

  1. GitHub Advisory GHSA-vmhg-wv2h-hgj7 · GitHub Advisory Database

Cite this entry

"Malicious code in @years19/n8n-nodes-utils-helper-y (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years19-n8n-nodes-utils-helper-y-npm-6zzfn8

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in checkout-desktop-total (npm)

    The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.

    npmCompromised package
  2. resolvedcritical

    Malicious code in epic-common-node (npm)

    The npm package epic-common-node was found to contain malicious code. The package has been identified and reported through GitHub Security Advisory GHSA-m36g-mhjr-ww2c.

    npmCompromised package
  3. containedcritical

    Malicious code in epic-common (npm)

    The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  4. containedcritical

    Malicious code in pfp-forms-sme-loan (npm)

    The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.

    npmCompromised packageMalicious commit