-= Per source details. Do not edit below this line.=-
Package presents as an n8n community node but is an attack artifact. The node's execute() in dist/SecurityTestNode.node.js queries AWS IMDSv1/v2 (http://169.254.169.254/latest/meta-data/iam/security-credentials/) and ECS metadata (169.254.170.2) for IAM role credentials, then iterates process.env to harvest every key matching /AWS|AMAZON|ECS|ECR/i, returning all of it in the node's workflow output. Any installer who adds this node to a workflow on an EC2/ECS host leaks the host IAM role's STS credentials and AWS env vars to the workflow output (which is typically persisted/logged) — direct AWS account compromise. The tarball additionally ships preinstall.js, which runs id && hostname && whoami && uname -a && cat /etc/os-release, writes /tmp/n8n-rce-proof.txt, and POSTs the recon output to https://worker.n8n-prod.schibsted.com/rest/variables (with rejectUnauthorized:false) and to 127.0.0.1:5678/rest/variables, using a hardcoded n8n-auth JWT cookie belonging to a third-party org's n8n deployment. package.json does not declare a preinstall lifecycle hook, so the recon payload does not auto-fire on npm install, but the file is bundled as a ready-to-run RCE proof and the JWT is redistributed to anyone who installs the package. The combination of (a) credential-harvest node code reachable on first workflow execution, (b) shipped exfiltration payload with hardcoded victim infrastructure, and (c) redistribution of a third-party auth token makes this an attack artifact regardless of the author's stated PoC framing.
{
"malicious-packages-origins": [
{
"import_time": "2026-06-17T18:56:06.758923767Z",
"sha256": "19c5e4a1ba8ae03bc1a47eeb38afb3e2834c395406239daa4f4bd8ac40a49019",
"modified_time": "2026-06-17T18:11:00Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-006917",
"versions": [
"1.0.5"
]
},
{
"import_time": "2026-06-17T18:56:06.849482132Z",
"sha256": "fa97d4701c29ef5305fa5b553ab560abd6db6cc33b72f99dc11621997b668f32",
"modified_time": "2026-06-17T18:11:01Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-006918",
"versions": [
"1.0.4"
]
},
{
"import_time": "2026-06-17T18:56:06.468601367Z",
"sha256": "55d0c9d23874a3ab1884195d5b6d7245520d4e67878bdf19cc5e1a5c2daea60c",
"modified_time": "2026-06-17T18:10:52Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-006914",
"versions": [
"1.0.1"
]
},
{
"import_time": "2026-06-17T18:56:06.659477358Z",
"sha256": "5aeb082546125cdff5d484ca56648143c4e1e173d261f93efff837cfa2d45487",
"modified_time": "2026-06-17T18:11:00Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-006916",
"versions": [
"1.0.2"
]
},
{
"import_time": "2026-06-17T18:56:06.581620674Z",
"source": "amazon-inspector",
"modified_time": "2026-06-17T18:11:00Z",
"sha256": "eece457251c8eef166dc093ef5c963ec0d1104d7ca1c7726a98948bc514777ae",
"id": "IN-MAL-2026-006915",
"versions": [
"1.0.3"
]
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/n8n-nodes-security-test-poc/MAL-2026-6071.json"
{
"evidence_files": [
{
"sha256": "724fa3f665e37d49dfda82d9c533d62bdd9b48f351dc65bc1cbc729a9be3987b",
"path": "dist/SecurityTestNode.node.js",
"tlsh": "6151441549f7616a14b3b95de32b600b6533d1036010eeacfbcd4721af0358c9eb17e8"
},
{
"sha256": "74345e893c3d0c6d985196d44ca744b2be0c54fe183d51aed3f4352d37c19d02",
"tlsh": "943122e278f6eb45aaf9a2f5656b82168427d151a061ee707acc12143fc931c9533ec4",
"path": "preinstall.js"
},
{
"sha256": "5038498bddd6ce70abe5cf5611159d6dcb472d42469e07307e0c2f0346cbb230",
"tlsh": "61d02e180c628a3314c84960097a9a083a280dab908afd0ca78b0408d29a5ba17b929c",
"path": "package.json"
}
],
"package_integrity": [
{
"filename": "n8n-nodes-security-test-poc-1.0.5.tgz",
"hashes": {
"sha512_sri": "sha512-4ABwM3TN4+VuuHIGC92bKvCfikKY1LHAk22Oo36m4lV4Q9sEnARGT2i/+9EbgUdwUHE+H7nKWpW0AcdRQpWf5g==",
"sha1": "1db38fa3b3b2c928b91e1a10c81ebf8f775badf9"
}
}
]
}
[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]