MAL-2026-10999

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/n8n-nodes-task-runner/MAL-2026-10999.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10999
Published
2026-07-22T20:24:15Z
Modified
2026-07-23T07:52:03.211046223Z
Summary
Malicious code in n8n-nodes-task-runner (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (991093c97f0d954740c4b72a2e7725a501df211c94634979ebadc52652f2ebe8)

The package impersonates the n8n task-runner subsystem but its shipped n8n node (MyNode.js) is a no-op stub whose execute() returns [[]]. The real payload lives in index.js (the package main), which runs a recon() function on module load. recon() reads ~/.aws/credentials, ~/.config/gcloud/applicationdefaultcredentials.json, ~/.azure/accessTokens.json, kubeconfig files, the Kubernetes service-account token, ~/.ssh/id_* and authorizedkeys, and environment variables matching token/key/secret/pass/auth/aws/gcp/azure/npm/github/gitlab. It also shells out via curl and childprocess to run id, ps aux, and read /proc/mounts, /proc/net/route, /etc/resolv.conf, /proc/1/cgroup, and arp; probes cloud instance-metadata services at 169.254.169.254 and metadata.google.internal; TCP-scans internal targets including the Docker API at 172.17.0.1:2375, an internal GKE API at 10.0.42.16:6443, Jenkins, and Kubernetes API endpoints; and enumerates /var/run/docker.sock. The aggregated JSON is POSTed to a hardcoded webhook.site collector at https://webhook.site/31b8dedb-f324-475f-8ffa-2b84878f4961. The n8n node stub exists only to make the package look like a legitimate community node while the credential stealer executes at require time.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "9b845c5b004a5fdb99bb2edcb3021579c2cd86ec0b8931cec5e63a6fea038c06",
            "modified_time": "2026-07-22T20:24:15Z",
            "versions": [
                "1.0.16"
            ],
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-010799",
            "import_time": "2026-07-22T20:31:07.702807605Z"
        },
        {
            "sha256": "82422ed3192d36068a21f9674c3f73ff94b55af03d6faf6debe9bb596fdb7964",
            "modified_time": "2026-07-22T20:37:34Z",
            "versions": [
                "1.0.1"
            ],
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-010835",
            "import_time": "2026-07-22T20:59:14.657216357Z"
        },
        {
            "sha256": "86ad8189bf3efbcf6db7e1a59006aaeeb0dd513c07b0226ee30fb0b945dba160",
            "modified_time": "2026-07-22T20:34:28Z",
            "id": "IN-MAL-2026-010815",
            "source": "amazon-inspector",
            "versions": [
                "1.0.7"
            ],
            "import_time": "2026-07-22T20:59:11.683687933Z"
        },
        {
            "sha256": "991093c97f0d954740c4b72a2e7725a501df211c94634979ebadc52652f2ebe8",
            "modified_time": "2026-07-22T20:34:56Z",
            "id": "IN-MAL-2026-010818",
            "source": "amazon-inspector",
            "versions": [
                "1.0.9"
            ],
            "import_time": "2026-07-22T20:59:12.066695522Z"
        },
        {
            "sha256": "bbdebb7b4e72738fd8ef5521d15047bd717c26793a3e48fdc28737db10d26945",
            "modified_time": "2026-07-22T20:35:20Z",
            "id": "IN-MAL-2026-010821",
            "source": "amazon-inspector",
            "versions": [
                "1.0.4"
            ],
            "import_time": "2026-07-22T20:59:12.618118594Z"
        },
        {
            "sha256": "c2578b1f3ee56446338624521781d7918716c29808fa17ba2c18294b194d526c",
            "modified_time": "2026-07-22T20:36:58Z",
            "id": "IN-MAL-2026-010831",
            "source": "amazon-inspector",
            "versions": [
                "1.0.2"
            ],
            "import_time": "2026-07-22T20:59:14.149873659Z"
        },
        {
            "sha256": "c63c7af0b43704ab3f64e074e8fa6a717d60ca7d205e9e53cae6e154272d282c",
            "modified_time": "2026-07-22T20:36:23Z",
            "id": "IN-MAL-2026-010828",
            "source": "amazon-inspector",
            "versions": [
                "1.0.3"
            ],
            "import_time": "2026-07-22T20:59:13.727131794Z"
        },
        {
            "sha256": "5889428ccaf926c79ba671feb8aa517bdc53550b3044191a389cd4d861c10624",
            "modified_time": "2026-07-22T20:34:39Z",
            "id": "IN-MAL-2026-010816",
            "source": "amazon-inspector",
            "versions": [
                "1.0.6"
            ],
            "import_time": "2026-07-22T20:59:11.790153963Z"
        },
        {
            "sha256": "c1ae6499cf4c2746e5aa5154d5dafc119da3e6b2f0f322db1dba47e639be682d",
            "modified_time": "2026-07-22T20:35:11Z",
            "id": "IN-MAL-2026-010820",
            "source": "amazon-inspector",
            "versions": [
                "1.0.8"
            ],
            "import_time": "2026-07-22T20:59:12.264340738Z"
        },
        {
            "sha256": "e35cbe39eb23c3ee35dae872cfb89e55ad3278d06ed3865f22b8ab4bb039d9ac",
            "modified_time": "2026-07-22T20:38:53Z",
            "id": "IN-MAL-2026-010845",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ],
            "import_time": "2026-07-22T20:59:15.866662745Z"
        },
        {
            "sha256": "fb228f3ff387ffce6619c11b82fa280660687b2da80caee00abc3fdd02075384",
            "modified_time": "2026-07-22T20:35:27Z",
            "versions": [
                "1.0.5"
            ],
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-010822",
            "import_time": "2026-07-22T20:59:12.738466959Z"
        }
    ]
}
References
Credits

Affected packages

npm / n8n-nodes-task-runner

Package

Name
n8n-nodes-task-runner
View open source insights on deps.dev
Purl
pkg:npm/n8n-nodes-task-runner

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.16

Database specific

indicators
{
    "evidence_files": [
        {
            "sha256": "23c6c3e602254a850e258e3c54ef7bf1cd0233d41e4ebf5ded15c159443a079b",
            "tlsh": "b0e184f074b4842b372650e8a68f3017bda7f62e286af5e4505d4d3c6d0e4d87136af5",
            "path": "index.js"
        }
    ],
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-jkKYalYZswHOl6TBL/cc0Qky7Ke2HKCCElI1T7aCjF7xjgIF2ju11XbuDsjjUUdJFhRJT14qmrHSbLMApNEF/Q==",
                "sha1": "d0c5708c477a71e2495876685171d15c0c99ccea"
            },
            "filename": "n8n-nodes-task-runner-1.0.16.tgz"
        }
    ]
}
cwes
[
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/n8n-nodes-task-runner/MAL-2026-10999.json"