Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in n8n-nodes-task-runner (npm)

0
Critical
Published: 07/22/2026 (07/22/2026, 20:24:15 UTC)
Source: GCVE Database
Product: n8n-nodes-task-runner

Description

The n8n-nodes-task-runner npm package contains malicious code that impersonates a legitimate n8n task-runner node. While the visible node component is a no-op stub, the main package code executes a reconnaissance function upon loading. This function collects sensitive credentials from cloud provider config files, SSH keys, environment variables, and probes internal network services and metadata endpoints. The collected data is exfiltrated to a hardcoded external webhook URL. This behavior enables credential theft and internal network reconnaissance.

Affected software

npmghsa
n8n-nodes-task-runner
Affected versions
=1.0.16=1.0.1=1.0.7=1.0.9=1.0.4=1.0.2=1.0.3=1.0.6=1.0.8=1.0.0=1.0.5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 23:41:38 UTC

Technical Analysis

The malicious n8n-nodes-task-runner package disguises itself as a legitimate n8n community node by including a no-op stub node. However, its main module runs a recon() function immediately when required. This function reads sensitive credential files from AWS, Google Cloud, Azure, Kubernetes, and SSH configurations, enumerates environment variables containing secrets, and executes system commands to gather system and network information. It also probes cloud instance metadata services and scans internal network endpoints including Docker and Kubernetes APIs. The aggregated reconnaissance data is sent as JSON to a hardcoded external collector URL at webhook.site. This package thus acts as a credential stealer and internal network reconnaissance tool.

Potential Impact

This malicious package can lead to the theft of cloud credentials, SSH keys, and other sensitive secrets from compromised systems. It also gathers detailed internal network and system information, potentially enabling further attacks or lateral movement. The exfiltration of this data to an external server compromises confidentiality and security of the affected environment.

Mitigation Recommendations

No official patch or remediation is currently available for this malicious package. Users should immediately remove any installations of n8n-nodes-task-runner versions =1.0.0 through =1.0.16. Avoid installing packages from untrusted sources and verify package authenticity before use. Monitor for any signs of credential compromise and rotate affected credentials. Since this is a malicious package impersonating a legitimate node, do not rely on the package's own code for mitigation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10999
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a6150ed9c2644c7f8da2cc5

Added to database: 07/22/2026, 23:23:25 UTC

Last enriched: 07/22/2026, 23:41:38 UTC

Last updated: 07/22/2026, 23:41:38 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses