Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in n8n-nodes-rce-poc (npm)

0
Critical
Published: 07/13/2026 (07/13/2026, 21:39:11 UTC)
Source: GCVE Database
Product: n8n-nodes-rce-poc

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (c735b8bb20a784446d7a0a4c49369ca3f2696bfe2e8a004799c763fc0a064aca) On require by n8n (module-load, top-level code in dist/RceNode.node.js), the package runs a shell command via execSync('/bin/sh',...). The command is taken from process.env.__N8N_RCE_CMD with a default of 'id && hostname && uname -a', so even an unconfigured install shells out and leaks host identity at load time, in the n8n host process and outside the vm2 sandbox. When process.env.__N8N_RCE_CB is set and EXEC_MODE is 'webhook' or 'both', the executed command's stdout/stderr/exitCode are serialized to JSON and HTTP-POSTed to the URL specified in __N8N_RCE_CB (dist/RceNode.node.js:28-40), giving a complete env-driven exfiltration channel to any destination. The node also exposes an execute() method that runs arbitrary user-supplied shell commands via /bin/sh on the n8n host, breaking the workflow Code-node sandbox model. The package.json description self-identifies as an 'n8n RCE proof-of-concept node'. There is no benign installer use: any n8n instance that installs this gains a drop-in remote-code-execution primitive plus a configurable exfiltration callback. ## Source: ghsa-malware (e557ecebe382eac94162c5402e89d9dade0b3c7c9a46efcef8dd762cdb2e61c3) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Affected software

npmghsa
n8n-nodes-rce-poc
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 09:49:24 UTC

Technical Analysis

The n8n-nodes-rce-poc package, when required by n8n, runs a shell command via execSync('/bin/sh', ...) using the environment variable __N8N_RCE_CMD or a default command that leaks host identity. If __N8N_RCE_CB is set and EXEC_MODE is 'webhook' or 'both', the command output is serialized and sent via HTTP POST to the specified callback URL, creating an exfiltration channel. The package exposes an execute() method allowing arbitrary shell command execution on the n8n host, breaking the sandbox model of n8n workflows. The package is self-identified as an RCE proof-of-concept and is inherently malicious with no benign installer use.

Potential Impact

Any n8n instance that installs this package gains a remote code execution primitive allowing arbitrary shell command execution on the host system. This leads to host information disclosure and potential full compromise through arbitrary command execution and data exfiltration to attacker-controlled endpoints. The sandbox protections of n8n workflows are bypassed, increasing the severity of the impact.

Mitigation Recommendations

No official patch or fix is available for this malicious package. The best mitigation is to avoid installing or using the n8n-nodes-rce-poc package, especially version 1.0.0. Remove the package if already installed and audit dependencies to prevent inclusion of this malicious code. Monitor for any unexpected environment variables like __N8N_RCE_CMD or __N8N_RCE_CB that could trigger the malicious behavior.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10503
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a55ff9068715ace432f4b33

Added to database: 07/14/2026, 09:21:20 UTC

Last enriched: 07/14/2026, 09:49:24 UTC

Last updated: 07/28/2026, 02:26:12 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses