Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @years20/n8n-nodes-utils-helper-a (npm)

The npm package @years20/n8n-nodes-utils-helper-a contained malicious code in its postinstall script and main module that performed system reconnaissance, exfiltrated SSH host keys, and attempted unauthorized SSH access to localhost. The payload communicated with an external command-and-control server at jasabersama.id.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any npm consumer installing @years20/n8n-nodes-utils-helper-a; particularly n8n users loading this custom node module.
Ecosystems
Attack vectors
Affected entities
  • @years20/n8n-nodes-utils-helper-aMalicious npm package containing reconnaissance and remote command execution code

The npm package @years20/n8n-nodes-utils-helper-a was published with embedded malicious code designed to execute automatically during installation and module import. The attack chain included two entry points: a postinstall script (callback.js) and the main module (index.js), both byte-identical and triggering on npm install and require().

The malicious payload performed system reconnaissance by collecting the output of id, hostname, WSL indicators, and SSH host-key fingerprints. This information was base64-encoded and exfiltrated to a hardcoded endpoint at https://jasabersama.id/portfolio-data.php with SSL certificate validation disabled.

The package also embedded a base64-encoded OpenSSH ed25519 private key, which was decoded and written to /tmp/pk with restricted permissions (chmod 600). The malware then attempted SSH brute-force access to localhost on ports 22495 and 22 using common account names (devuser, ubuntu, runner, node, root, chris, user), reporting successful logins back to the external command server.

The exfiltration payload included a URL-encoded shell command parameter, indicating the receiving PHP handler was designed to execute arbitrary commands server-side, establishing a persistent remote command channel.

Indicators of compromise

Packages
  • @years20/n8n-nodes-utils-helper-a
Domains
  • jasabersama.id

Remediation

  • Immediately uninstall @years20/n8n-nodes-utils-helper-a from all systems
  • Audit npm install logs and process execution history for any systems that installed this package
  • Rotate SSH keys and credentials on any affected systems, particularly for accounts listed in the malware (devuser, ubuntu, runner, node, root, chris, user)
  • Check for unauthorized SSH access attempts or successful logins on ports 22 and 22495
  • Review network egress logs for connections to jasabersama.id and similar suspicious domains
  • Scan systems for the presence of /tmp/pk or other artifacts left by the malware
  • Update npm dependencies and use npm audit to identify and remove any remaining malicious packages
  • Consider implementing package signature verification and supply chain security scanning in CI/CD pipelines

Sources

  1. GitHub Advisory GHSA-v74f-fw7q-mj8v · GitHub Advisory Database

Cite this entry

"Malicious code in @years20/n8n-nodes-utils-helper-a (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 12, 2026; last updated August 12, 2026. https://supplychainattack.org/incident/malicious-code-in-years20-n8n-nodes-utils-helper-a-npm-l18q0a

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in epic-sso (npm)

    The npm package epic-sso was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  2. containedcritical

    Malicious code in pfp-forms-sme-loan (npm)

    The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.

    npmCompromised packageMalicious commit
  3. containedcritical

    Malicious code in checkout-desktop-total (npm)

    The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.

    npmCompromised package
  4. containedcritical

    Malicious code in epic-common (npm)

    The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package