npm · Malicious package advisory
Malware@years18/n8n-nodes-utils-helper-x
GHSA-hr4h-q7h6-65hr
Malicious code in @years18/n8n-nodes-utils-helper-x (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (6db9e566808d6a2ce38311e17939cd39ba94fc191cf5c44ab7b08b369840ba08) Package presents itself as an n8n utility helper but ships a 213-byte stub node and a hostile postinstall (`node callback.js`). On `npm install`, callback.js fetches two tarballs (impacket.tgz, pyroxy.tgz) over HTTPS with TLS verification disabled from jasabersama.id/assets/cache/.theme-backup/dl/, extracts them into the installer's Python user site-packages so any subsequent Python import runs attacker-controlled code, and probes /tmp/mhddos/start.py (MHDDoS DDoS tooling). The same script collects `id` and `hostname` command output plus install-step status, base64-encodes the buffer, and sends it via HTTPS GET to https://jasabersama.id/portfolio-data.php as a URL parameter, indexing compromised hosts. The declared package purpose does not match the shipped behavior; the host is publisher-mismatched and TLS verification is disabled. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/06026f151d0406abcf51e273cdbe9620a0487d26/osv/malicious/npm/@years18/n8n-nodes-utils-helper-x/MAL-2026-13868.json)) **References:** - https://github.com/ossf/malicious-packages/blob/06026f151d0406abcf51e273cdbe9620a0487d26/osv/malicious/npm/@years18/n8n-nodes-utils-helper-x/MAL-2026-13868.json - https://www.npmjs.com/package/@years18/n8n-nodes-utils-helper-x/v/1.0.0 - https://github.com/advisories/GHSA-hr4h-q7h6-65hr
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.