MAL-2026-6071

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/n8n-nodes-security-test-poc/MAL-2026-6071.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-6071
Published
2026-06-17T18:10:52Z
Modified
2026-06-17T19:01:50.972870524Z
Summary
Malicious code in n8n-nodes-security-test-poc (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (fa97d4701c29ef5305fa5b553ab560abd6db6cc33b72f99dc11621997b668f32)

Package presents as an n8n community node but is an attack artifact. The node's execute() in dist/SecurityTestNode.node.js queries AWS IMDSv1/v2 (http://169.254.169.254/latest/meta-data/iam/security-credentials/) and ECS metadata (169.254.170.2) for IAM role credentials, then iterates process.env to harvest every key matching /AWS|AMAZON|ECS|ECR/i, returning all of it in the node's workflow output. Any installer who adds this node to a workflow on an EC2/ECS host leaks the host IAM role's STS credentials and AWS env vars to the workflow output (which is typically persisted/logged) — direct AWS account compromise. The tarball additionally ships preinstall.js, which runs id && hostname && whoami && uname -a && cat /etc/os-release, writes /tmp/n8n-rce-proof.txt, and POSTs the recon output to https://worker.n8n-prod.schibsted.com/rest/variables (with rejectUnauthorized:false) and to 127.0.0.1:5678/rest/variables, using a hardcoded n8n-auth JWT cookie belonging to a third-party org's n8n deployment. package.json does not declare a preinstall lifecycle hook, so the recon payload does not auto-fire on npm install, but the file is bundled as a ready-to-run RCE proof and the JWT is redistributed to anyone who installs the package. The combination of (a) credential-harvest node code reachable on first workflow execution, (b) shipped exfiltration payload with hardcoded victim infrastructure, and (c) redistribution of a third-party auth token makes this an attack artifact regardless of the author's stated PoC framing.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-06-17T18:56:06.758923767Z",
            "sha256": "19c5e4a1ba8ae03bc1a47eeb38afb3e2834c395406239daa4f4bd8ac40a49019",
            "modified_time": "2026-06-17T18:11:00Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-006917",
            "versions": [
                "1.0.5"
            ]
        },
        {
            "import_time": "2026-06-17T18:56:06.849482132Z",
            "sha256": "fa97d4701c29ef5305fa5b553ab560abd6db6cc33b72f99dc11621997b668f32",
            "modified_time": "2026-06-17T18:11:01Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-006918",
            "versions": [
                "1.0.4"
            ]
        },
        {
            "import_time": "2026-06-17T18:56:06.468601367Z",
            "sha256": "55d0c9d23874a3ab1884195d5b6d7245520d4e67878bdf19cc5e1a5c2daea60c",
            "modified_time": "2026-06-17T18:10:52Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-006914",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "import_time": "2026-06-17T18:56:06.659477358Z",
            "sha256": "5aeb082546125cdff5d484ca56648143c4e1e173d261f93efff837cfa2d45487",
            "modified_time": "2026-06-17T18:11:00Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-006916",
            "versions": [
                "1.0.2"
            ]
        },
        {
            "import_time": "2026-06-17T18:56:06.581620674Z",
            "source": "amazon-inspector",
            "modified_time": "2026-06-17T18:11:00Z",
            "sha256": "eece457251c8eef166dc093ef5c963ec0d1104d7ca1c7726a98948bc514777ae",
            "id": "IN-MAL-2026-006915",
            "versions": [
                "1.0.3"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / n8n-nodes-security-test-poc

Package

Name
n8n-nodes-security-test-poc
View open source insights on deps.dev
Purl
pkg:npm/n8n-nodes-security-test-poc

Affected ranges

Affected versions

1.*
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/n8n-nodes-security-test-poc/MAL-2026-6071.json"
indicators
{
    "evidence_files": [
        {
            "sha256": "724fa3f665e37d49dfda82d9c533d62bdd9b48f351dc65bc1cbc729a9be3987b",
            "path": "dist/SecurityTestNode.node.js",
            "tlsh": "6151441549f7616a14b3b95de32b600b6533d1036010eeacfbcd4721af0358c9eb17e8"
        },
        {
            "sha256": "74345e893c3d0c6d985196d44ca744b2be0c54fe183d51aed3f4352d37c19d02",
            "tlsh": "943122e278f6eb45aaf9a2f5656b82168427d151a061ee707acc12143fc931c9533ec4",
            "path": "preinstall.js"
        },
        {
            "sha256": "5038498bddd6ce70abe5cf5611159d6dcb472d42469e07307e0c2f0346cbb230",
            "tlsh": "61d02e180c628a3314c84960097a9a083a280dab908afd0ca78b0408d29a5ba17b929c",
            "path": "package.json"
        }
    ],
    "package_integrity": [
        {
            "filename": "n8n-nodes-security-test-poc-1.0.5.tgz",
            "hashes": {
                "sha512_sri": "sha512-4ABwM3TN4+VuuHIGC92bKvCfikKY1LHAk22Oo36m4lV4Q9sEnARGT2i/+9EbgUdwUHE+H7nKWpW0AcdRQpWf5g==",
                "sha1": "1db38fa3b3b2c928b91e1a10c81ebf8f775badf9"
            }
        }
    ]
}
cwes
[
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    }
]