Malicious code in @years19/n8n-nodes-utils-helper-y (npm)
The npm package @years19/n8n-nodes-utils-helper-y contained malicious code that executes on install and on every require, launching DDoS attacks and exfiltrating host identity information to a remote server.
- Disclosed
- Last updated
- Blast radius
- Any system installing or requiring @years19/n8n-nodes-utils-helper-y
- Ecosystems
- Attack vectors
- Affected entities
- @years19/n8n-nodes-utils-helper-yMalicious npm package masquerading as n8n community utility helper node
The package @years19/n8n-nodes-utils-helper-y was published to npm with malicious intent, disguised as a legitimate n8n community utility helper node. The package.json declared a postinstall hook and a main entry point, both containing identical malicious code.\n\nUpon installation or when the package is required, the malicious code executes in two stages: (1) it writes a Python script to /tmp/attack2.py and launches it via nohup, which floods the IP address 103.118.252.21 on ports 80 and 443 with UDP/TCP traffic using 2000 threads for 900 seconds; and (2) it collects host identity information including uid, hostname, and process/load data, base64-encodes it, and sends it over HTTPS GET to jasabersama.id/portfolio-data.php with TLS certificate verification disabled.\n\nBecause the malicious code is present in both the postinstall script and the top-level module code, it executes both during npm install and every time a consumer requires the package or n8n loads the node, creating persistent compromise.\n\nThe incident was identified and reported by the OpenSSF malicious-packages project.
Indicators of compromise
- Packages
- @years19/n8n-nodes-utils-helper-y
- Domains
- jasabersama.id
- IPs
- 103.118.252.21
Remediation
- Immediately uninstall @years19/n8n-nodes-utils-helper-y from all systems
- Audit npm install logs and process history for execution of callback.js and /tmp/attack2.py
- Review network logs for outbound traffic to 103.118.252.21 (ports 80/443) and jasabersama.id
- Check for any HTTPS GET requests to jasabersama.id/portfolio-data.php
- Regenerate credentials and review access logs on affected systems
- Block the malicious domains and IP addresses at the network perimeter
- Use npm audit to identify any other malicious packages in your dependency tree
Sources
- GitHub Advisory GHSA-vmhg-wv2h-hgj7 · GitHub Advisory Database
Cite this entry
"Malicious code in @years19/n8n-nodes-utils-helper-y (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years19-n8n-nodes-utils-helper-y-npm-6zzfn8
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in checkout-desktop-total (npm)
The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.
npmCompromised package - resolvedcritical
Malicious code in epic-common-node (npm)
The npm package epic-common-node was found to contain malicious code. The package has been identified and reported through GitHub Security Advisory GHSA-m36g-mhjr-ww2c.
npmCompromised package - containedcritical
Malicious code in epic-common (npm)
The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package - containedcritical
Malicious code in pfp-forms-sme-loan (npm)
The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.
npmCompromised packageMalicious commit