-= Per source details. Do not edit below this line.=-
The package impersonates the n8n task-runner subsystem but its shipped n8n node (MyNode.js) is a no-op stub whose execute() returns [[]]. The real payload lives in index.js (the package main), which runs a recon() function on module load. recon() reads ~/.aws/credentials, ~/.config/gcloud/application_default_credentials.json, ~/.azure/accessTokens.json, kubeconfig files, the Kubernetes service-account token, ~/.ssh/id_* and authorized_keys, and environment variables matching token/key/secret/pass/auth/aws/gcp/azure/npm/github/gitlab. It also shells out via curl and child_process to run id, ps aux, and read /proc/mounts, /proc/net/route, /etc/resolv.conf, /proc/1/cgroup, and arp; probes cloud instance-metadata services at 169.254.169.254 and metadata.google.internal; TCP-scans internal targets including the Docker API at 172.17.0.1:2375, an internal GKE API at 10.0.42.16:6443, Jenkins, and Kubernetes API endpoints; and enumerates /var/run/docker.sock. The aggregated JSON is POSTed to a hardcoded webhook.site collector at https://webhook.site/31b8dedb-f324-475f-8ffa-2b84878f4961. The n8n node stub exists only to make the package look like a legitimate community node while the credential stealer executes at require time.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-010799",
"import_time": "2026-07-22T20:31:07.702807605Z",
"modified_time": "2026-07-22T20:24:15Z",
"sha256": "9b845c5b004a5fdb99bb2edcb3021579c2cd86ec0b8931cec5e63a6fea038c06",
"source": "amazon-inspector",
"versions": [
"1.0.16"
]
},
{
"id": "IN-MAL-2026-010835",
"import_time": "2026-07-22T20:59:14.657216357Z",
"modified_time": "2026-07-22T20:37:34Z",
"sha256": "82422ed3192d36068a21f9674c3f73ff94b55af03d6faf6debe9bb596fdb7964",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-010815",
"import_time": "2026-07-22T20:59:11.683687933Z",
"modified_time": "2026-07-22T20:34:28Z",
"sha256": "86ad8189bf3efbcf6db7e1a59006aaeeb0dd513c07b0226ee30fb0b945dba160",
"source": "amazon-inspector",
"versions": [
"1.0.7"
]
},
{
"id": "IN-MAL-2026-010818",
"import_time": "2026-07-22T20:59:12.066695522Z",
"modified_time": "2026-07-22T20:34:56Z",
"sha256": "991093c97f0d954740c4b72a2e7725a501df211c94634979ebadc52652f2ebe8",
"source": "amazon-inspector",
"versions": [
"1.0.9"
]
},
{
"id": "IN-MAL-2026-010821",
"import_time": "2026-07-22T20:59:12.618118594Z",
"modified_time": "2026-07-22T20:35:20Z",
"sha256": "bbdebb7b4e72738fd8ef5521d15047bd717c26793a3e48fdc28737db10d26945",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
},
{
"id": "IN-MAL-2026-010831",
"import_time": "2026-07-22T20:59:14.149873659Z",
"modified_time": "2026-07-22T20:36:58Z",
"sha256": "c2578b1f3ee56446338624521781d7918716c29808fa17ba2c18294b194d526c",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
},
{
"id": "IN-MAL-2026-010828",
"import_time": "2026-07-22T20:59:13.727131794Z",
"modified_time": "2026-07-22T20:36:23Z",
"sha256": "c63c7af0b43704ab3f64e074e8fa6a717d60ca7d205e9e53cae6e154272d282c",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
},
{
"id": "IN-MAL-2026-010816",
"import_time": "2026-07-22T20:59:11.790153963Z",
"modified_time": "2026-07-22T20:34:39Z",
"sha256": "5889428ccaf926c79ba671feb8aa517bdc53550b3044191a389cd4d861c10624",
"source": "amazon-inspector",
"versions": [
"1.0.6"
]
},
{
"id": "IN-MAL-2026-010820",
"import_time": "2026-07-22T20:59:12.264340738Z",
"modified_time": "2026-07-22T20:35:11Z",
"sha256": "c1ae6499cf4c2746e5aa5154d5dafc119da3e6b2f0f322db1dba47e639be682d",
"source": "amazon-inspector",
"versions": [
"1.0.8"
]
},
{
"id": "IN-MAL-2026-010845",
"import_time": "2026-07-22T20:59:15.866662745Z",
"modified_time": "2026-07-22T20:38:53Z",
"sha256": "e35cbe39eb23c3ee35dae872cfb89e55ad3278d06ed3865f22b8ab4bb039d9ac",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-010822",
"import_time": "2026-07-22T20:59:12.738466959Z",
"modified_time": "2026-07-22T20:35:27Z",
"sha256": "fb228f3ff387ffce6619c11b82fa280660687b2da80caee00abc3fdd02075384",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
},
{
"id": "IN-MAL-2026-010884",
"import_time": "2026-07-28T14:19:57.395640981Z",
"modified_time": "2026-07-28T13:31:31Z",
"sha256": "0fc1373bdb7a7054ff27a7cb5acc9b2ab966003f3d74b960eeb25dff97a505c0",
"source": "amazon-inspector",
"versions": [
"1.0.15"
]
},
{
"id": "IN-MAL-2026-010895",
"import_time": "2026-07-28T14:19:57.946004398Z",
"modified_time": "2026-07-28T13:33:00Z",
"sha256": "1e5996e859e78730213d45f2b66f6d3cda5c1ba0afef27dfe2ca0ef5f45ab9c6",
"source": "amazon-inspector",
"versions": [
"1.0.11"
]
},
{
"id": "IN-MAL-2026-010894",
"import_time": "2026-07-28T14:19:57.909836095Z",
"modified_time": "2026-07-28T13:32:52Z",
"sha256": "751bb1279f3e171656709d21ef41f14640a9520cfaa6f157ce285b305475aea7",
"source": "amazon-inspector",
"versions": [
"1.0.13"
]
},
{
"id": "IN-MAL-2026-010896",
"import_time": "2026-07-28T14:19:57.991865758Z",
"modified_time": "2026-07-28T13:33:06Z",
"sha256": "bbcf9f8b8f60a4da1972ff09ac408baee5dc99ebe51e288748f18473ebde98b3",
"source": "amazon-inspector",
"versions": [
"1.0.12"
]
},
{
"id": "IN-MAL-2026-010900",
"import_time": "2026-07-28T14:19:58.186319405Z",
"modified_time": "2026-07-28T13:33:38Z",
"sha256": "c19550780700c81f7eb977b968397723aac952f1d935a1de19ce9f3ab2ab4366",
"source": "amazon-inspector",
"versions": [
"1.0.10"
]
},
{
"id": "IN-MAL-2026-010886",
"import_time": "2026-07-28T14:19:57.490788197Z",
"modified_time": "2026-07-28T13:31:49Z",
"sha256": "f41a8a9ddba88c38f17ffbe3882f1754f3a1c693d2c43dcd8a0264262d6fd85f",
"source": "amazon-inspector",
"versions": [
"1.0.14"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "23c6c3e602254a850e258e3c54ef7bf1cd0233d41e4ebf5ded15c159443a079b",
"tlsh": "b0e184f074b4842b372650e8a68f3017bda7f62e286af5e4505d4d3c6d0e4d87136af5"
}
],
"package_integrity": [
{
"filename": "n8n-nodes-task-runner-1.0.16.tgz",
"hashes": {
"sha1": "d0c5708c477a71e2495876685171d15c0c99ccea",
"sha512_sri": "sha512-jkKYalYZswHOl6TBL/cc0Qky7Ke2HKCCElI1T7aCjF7xjgIF2ju11XbuDsjjUUdJFhRJT14qmrHSbLMApNEF/Q=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/n8n-nodes-task-runner/MAL-2026-10999.json"