-= Per source details. Do not edit below this line.=-
The package impersonates the n8n task-runner subsystem but its shipped n8n node (MyNode.js) is a no-op stub whose execute() returns [[]]. The real payload lives in index.js (the package main), which runs a recon() function on module load. recon() reads ~/.aws/credentials, ~/.config/gcloud/applicationdefaultcredentials.json, ~/.azure/accessTokens.json, kubeconfig files, the Kubernetes service-account token, ~/.ssh/id_* and authorizedkeys, and environment variables matching token/key/secret/pass/auth/aws/gcp/azure/npm/github/gitlab. It also shells out via curl and childprocess to run id, ps aux, and read /proc/mounts, /proc/net/route, /etc/resolv.conf, /proc/1/cgroup, and arp; probes cloud instance-metadata services at 169.254.169.254 and metadata.google.internal; TCP-scans internal targets including the Docker API at 172.17.0.1:2375, an internal GKE API at 10.0.42.16:6443, Jenkins, and Kubernetes API endpoints; and enumerates /var/run/docker.sock. The aggregated JSON is POSTed to a hardcoded webhook.site collector at https://webhook.site/31b8dedb-f324-475f-8ffa-2b84878f4961. The n8n node stub exists only to make the package look like a legitimate community node while the credential stealer executes at require time.
{
"malicious-packages-origins": [
{
"sha256": "9b845c5b004a5fdb99bb2edcb3021579c2cd86ec0b8931cec5e63a6fea038c06",
"modified_time": "2026-07-22T20:24:15Z",
"versions": [
"1.0.16"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-010799",
"import_time": "2026-07-22T20:31:07.702807605Z"
},
{
"sha256": "82422ed3192d36068a21f9674c3f73ff94b55af03d6faf6debe9bb596fdb7964",
"modified_time": "2026-07-22T20:37:34Z",
"versions": [
"1.0.1"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-010835",
"import_time": "2026-07-22T20:59:14.657216357Z"
},
{
"sha256": "86ad8189bf3efbcf6db7e1a59006aaeeb0dd513c07b0226ee30fb0b945dba160",
"modified_time": "2026-07-22T20:34:28Z",
"id": "IN-MAL-2026-010815",
"source": "amazon-inspector",
"versions": [
"1.0.7"
],
"import_time": "2026-07-22T20:59:11.683687933Z"
},
{
"sha256": "991093c97f0d954740c4b72a2e7725a501df211c94634979ebadc52652f2ebe8",
"modified_time": "2026-07-22T20:34:56Z",
"id": "IN-MAL-2026-010818",
"source": "amazon-inspector",
"versions": [
"1.0.9"
],
"import_time": "2026-07-22T20:59:12.066695522Z"
},
{
"sha256": "bbdebb7b4e72738fd8ef5521d15047bd717c26793a3e48fdc28737db10d26945",
"modified_time": "2026-07-22T20:35:20Z",
"id": "IN-MAL-2026-010821",
"source": "amazon-inspector",
"versions": [
"1.0.4"
],
"import_time": "2026-07-22T20:59:12.618118594Z"
},
{
"sha256": "c2578b1f3ee56446338624521781d7918716c29808fa17ba2c18294b194d526c",
"modified_time": "2026-07-22T20:36:58Z",
"id": "IN-MAL-2026-010831",
"source": "amazon-inspector",
"versions": [
"1.0.2"
],
"import_time": "2026-07-22T20:59:14.149873659Z"
},
{
"sha256": "c63c7af0b43704ab3f64e074e8fa6a717d60ca7d205e9e53cae6e154272d282c",
"modified_time": "2026-07-22T20:36:23Z",
"id": "IN-MAL-2026-010828",
"source": "amazon-inspector",
"versions": [
"1.0.3"
],
"import_time": "2026-07-22T20:59:13.727131794Z"
},
{
"sha256": "5889428ccaf926c79ba671feb8aa517bdc53550b3044191a389cd4d861c10624",
"modified_time": "2026-07-22T20:34:39Z",
"id": "IN-MAL-2026-010816",
"source": "amazon-inspector",
"versions": [
"1.0.6"
],
"import_time": "2026-07-22T20:59:11.790153963Z"
},
{
"sha256": "c1ae6499cf4c2746e5aa5154d5dafc119da3e6b2f0f322db1dba47e639be682d",
"modified_time": "2026-07-22T20:35:11Z",
"id": "IN-MAL-2026-010820",
"source": "amazon-inspector",
"versions": [
"1.0.8"
],
"import_time": "2026-07-22T20:59:12.264340738Z"
},
{
"sha256": "e35cbe39eb23c3ee35dae872cfb89e55ad3278d06ed3865f22b8ab4bb039d9ac",
"modified_time": "2026-07-22T20:38:53Z",
"id": "IN-MAL-2026-010845",
"source": "amazon-inspector",
"versions": [
"1.0.0"
],
"import_time": "2026-07-22T20:59:15.866662745Z"
},
{
"sha256": "fb228f3ff387ffce6619c11b82fa280660687b2da80caee00abc3fdd02075384",
"modified_time": "2026-07-22T20:35:27Z",
"versions": [
"1.0.5"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-010822",
"import_time": "2026-07-22T20:59:12.738466959Z"
}
]
}{
"evidence_files": [
{
"sha256": "23c6c3e602254a850e258e3c54ef7bf1cd0233d41e4ebf5ded15c159443a079b",
"tlsh": "b0e184f074b4842b372650e8a68f3017bda7f62e286af5e4505d4d3c6d0e4d87136af5",
"path": "index.js"
}
],
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-jkKYalYZswHOl6TBL/cc0Qky7Ke2HKCCElI1T7aCjF7xjgIF2ju11XbuDsjjUUdJFhRJT14qmrHSbLMApNEF/Q==",
"sha1": "d0c5708c477a71e2495876685171d15c0c99ccea"
},
"filename": "n8n-nodes-task-runner-1.0.16.tgz"
}
]
}
[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/n8n-nodes-task-runner/MAL-2026-10999.json"