-= Per source details. Do not edit below this line.=-
Package ships a malicious n8n community node with three independent installer-harm paths. (1) package.json declares a postinstall script that shells out via node -e to run id and hostname and writes the output to /tmp/pwned.txt at npm install time. (2) The package main (index.js) executes id; hostname; uname -a; ls -la /home; cat /etc/hostname at top-level on require() and writes the collected data to /tmp/n8n_pwned.txt; comments in the file explicitly acknowledge it runs inside n8n's main process with no sandbox, and n8n auto-loads community node packages on startup. (3) The exported HelperUtils node's execute() unconditionally runs id; hostname; uname -a; ls -la /home; ls -la / and returns the output as node output labelled pwned: true, rather than performing the utility transformation the package name advertises. The three payloads together, along with the self-identifying pwned filenames and output flags, are a proof-of-concept malicious n8n node that gains code execution on the installer host at install, on module load, and on workflow execution.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017564",
"import_time": "2026-08-12T12:51:50.60523037Z",
"modified_time": "2026-08-12T12:39:16Z",
"sha256": "4ffb2107eaa9c9aa6c8ce0fc81b09954b9e29b16acef67075c3c0bfd6d25fcc4",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
},
{
"id": "IN-MAL-2026-017562",
"import_time": "2026-08-12T12:51:50.498528645Z",
"modified_time": "2026-08-12T12:39:03Z",
"sha256": "80e76cec0eccb25ba0dc8863218767daffe706e19095a36d9bbdb8f9569b2027",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
},
{
"id": "IN-MAL-2026-017566",
"import_time": "2026-08-12T12:51:50.749615163Z",
"modified_time": "2026-08-12T12:39:36Z",
"sha256": "8e6ad4ba67340980f04fda62f7c0df3a3770247910344011fa185277ef5ca484",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-017569",
"import_time": "2026-08-12T12:51:50.91928513Z",
"modified_time": "2026-08-12T12:40:03Z",
"sha256": "9b93e5585c4cc3967188b6b9b4a1f6a89d3d8060fd28daf511849b44145a645c",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-017563",
"import_time": "2026-08-12T12:51:50.542641871Z",
"modified_time": "2026-08-12T12:39:09Z",
"sha256": "fcd670acb1a3ca75ca78fd2db4dff1a579135727bafa9c4edc7df81fb545fcb5",
"source": "amazon-inspector",
"versions": [
"1.0.6"
]
},
{
"id": "IN-MAL-2026-017561",
"import_time": "2026-08-12T12:51:50.441852442Z",
"modified_time": "2026-08-12T12:38:55Z",
"sha256": "64819454fc9d9904917336a6e36102f0925718ad2f4eab2d6673d75ff68fe777",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
},
{
"id": "IN-MAL-2026-017565",
"import_time": "2026-08-12T12:51:50.685674979Z",
"modified_time": "2026-08-12T12:39:25Z",
"sha256": "6ea8ef8dbe7f0a9d503e743a079c961b6b9fb7f837e7e52ce2e745ef4e14f5a9",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "05f69536796b2f3b78a2b6ee3050b37ccd4b77a8593a0b7264f471246b84c340",
"tlsh": "2bf095124d745f3361c406236959404167259957414c7c2473cf025d83ec7fa2a7f579"
},
{
"path": "index.js",
"sha256": "a2066f0b8dabc316066cab423c5f284f9f856ae0548e35ddea723b3802b474f1",
"tlsh": "09e026e2fa7cd3a131e56495e55b44112c96c149e01167e099cd8deb03ca10f0b538f2"
},
{
"path": "nodes/PwnNode.node.js",
"sha256": "40b53448a84cc9eaf7e701d6e8301f5257988eb9b6664a8085bb624db7beff6b",
"tlsh": "4cf050d19975e3511052ac55bb4796022866d2075a31bc35b48d8a930f0d20da2b5cf8"
}
],
"package_integrity": [
{
"filename": "n8n-nodes-helper-utils-1.0.2.tgz",
"hashes": {
"sha1": "4581cd90c469d2b0a24fea6485b71bee2b8a1df1",
"sha512_sri": "sha512-77FnVkVxgDxkZvbnANyLCKrGAr8/AhiIrGOlu5aSj9FqUeeWauiDUpmecsm3jD1Ds4PeWSBWquoNR2Kieh2s7Q=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@years17/n8n-nodes-helper-utils/MAL-2026-13869.json"