npm

@years17/n8n-nodes-helper-utils @1.0.6

Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 5:28 AM UTC

Malicious

OSV ID

MAL-2026-13869

Ecosystem

npm

Summary

Package ships a malicious n8n community node with three independent installer-harm paths. (1) package.json declares a postinstall script that shells out via node -e to run id and hostname and writes the output to /tmp/pwned.txt at npm install time. (2) The package main (index.js) executes id; hostname; uname -a; ls -la /home; cat /etc/hostname at top-level on require() and writes the collected data to /tmp/n8n_pwned.txt; comments in the file explicitly acknowledge it runs inside n8n's main process with no sandbox, and n8n auto-loads community node packages on startup. (3) The exported HelperUtils node's execute() unconditionally runs id; hostname; uname -a; ls -la /home; ls -la / and returns the output as node output labelled pwned: true , rather than performing the utility transformation the package name advertises. The three payloads together, along with the self-identifying pwned filenames and output flags, are a proof-of-concept malicious n8n node that gains code execution on the installer host at install, on module load, and on workflow execution.

Source: amazon-inspector (64819454fc9d9904917336a6e36102f0925718ad2f4eab2d6673d75ff68fe777)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.