-= Per source details. Do not edit below this line.=-
On npm install, this package auto-runs callback.js via a postinstall hook (and repeats the same behavior in index.js on require). The script shells out to install pip from /tmp/get-pip.py, then installs requirements for and launches an mhddos DDoS toolkit staged at /tmp/mhddos (python3 start.py), and probes an internal-network address at 10.131.106.93:8888. It then collects installer identity via id and hostname plus command output, base64-encodes the results, and sends them as a query string to https://jasabersama.id/portfolio-data.php with TLS verification disabled (rejectUnauthorized:false). The URL carries a c= parameter containing a shell command written to /tmp/n8nrceresult.txt, structured as a keyed (k=S7k9xQ2mZj) command channel consistent with a staged RCE relay on the attacker's server. The package name resembles a helper for n8n but its only shipped behavior is dropper, DDoS-tool bootstrap, and exfiltration.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017408",
"import_time": "2026-08-12T12:24:10.747863677Z",
"sha256": "d70df151b0a3f6d74618b466c9d7ac91e18389b38a805e2010b55202b5722330",
"modified_time": "2026-08-12T12:17:28Z",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"path": "callback.js",
"tlsh": "a93165f42350e1348a13a0d47a27e956f4abf2071098bbc8f58f42738b23954ab5316d",
"sha256": "4cebce1f6b6c2155570f01ea57fa54308ce2cc2f8b0f7367ca33c14c0bf8d8ec"
}
],
"package_integrity": [
{
"filename": "n8n-nodes-utils-helper-e-1.0.0.tgz",
"hashes": {
"sha512_sri": "sha512-qkMx6GrWzzy+3C2DZqlVI+jdkn46Rbu8tfEbOXQndRJcNC3konKCQNk4bgEy8N3PqN2lUxn4rx5m0WbMusx3Hw==",
"sha1": "bb48d504bdb7252d47d97955f76f74f76aafcd3d"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@years18/n8n-nodes-utils-helper-e/MAL-2026-13851.json"