Malicious code in @years19/n8n-nodes-utils-helper-f (npm)
The npm package @years19/n8n-nodes-utils-helper-f version 1.0.0 contains malicious code that executes during installation and when required. It collects host identity and environment information, encodes it, and sends it to an attacker-controlled server with TLS verification disabled. The package masquerades as a legitimate n8n community node but functions as a beacon for attacker command and control.
AI Analysis
Technical Summary
The package @years19/n8n-nodes-utils-helper-f (version 1.0.0) includes a postinstall script that gathers system identity and environment fingerprint data, including user and hostname information and the presence of certain offensive tooling. This data is base64-encoded and sent via an HTTP request with disabled TLS verification to https://jasabersama.id/portfolio-data.php, including a hardcoded key and a command injection pattern that writes decoded data to a temporary file. Both installation and requiring the package trigger this behavior. The package name mimics legitimate n8n community nodes, but the main module contains the same malicious code as the postinstall script, indicating intent to stealthily exfiltrate data and maintain a command channel.
Potential Impact
The malicious package exfiltrates sensitive host and environment information to an attacker-controlled server without user consent, potentially exposing system details that could aid further attacks. The disabled TLS verification increases the risk of interception or manipulation of the exfiltrated data. The package's behavior could facilitate persistent attacker presence or command execution on affected systems.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately remove the package @years19/n8n-nodes-utils-helper-f version 1.0.0 from their environments and avoid installing or requiring it. Verify dependencies to ensure this malicious package is not included transitively. Monitor for any signs of compromise related to this package and consider network controls to block communication to the indicated attacker domain. Patch status is not yet confirmed — check the vendor advisory or trusted sources for updates.
Malicious code in @years19/n8n-nodes-utils-helper-f (npm)
Description
The npm package @years19/n8n-nodes-utils-helper-f version 1.0.0 contains malicious code that executes during installation and when required. It collects host identity and environment information, encodes it, and sends it to an attacker-controlled server with TLS verification disabled. The package masquerades as a legitimate n8n community node but functions as a beacon for attacker command and control.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The package @years19/n8n-nodes-utils-helper-f (version 1.0.0) includes a postinstall script that gathers system identity and environment fingerprint data, including user and hostname information and the presence of certain offensive tooling. This data is base64-encoded and sent via an HTTP request with disabled TLS verification to https://jasabersama.id/portfolio-data.php, including a hardcoded key and a command injection pattern that writes decoded data to a temporary file. Both installation and requiring the package trigger this behavior. The package name mimics legitimate n8n community nodes, but the main module contains the same malicious code as the postinstall script, indicating intent to stealthily exfiltrate data and maintain a command channel.
Potential Impact
The malicious package exfiltrates sensitive host and environment information to an attacker-controlled server without user consent, potentially exposing system details that could aid further attacks. The disabled TLS verification increases the risk of interception or manipulation of the exfiltrated data. The package's behavior could facilitate persistent attacker presence or command execution on affected systems.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately remove the package @years19/n8n-nodes-utils-helper-f version 1.0.0 from their environments and avoid installing or requiring it. Verify dependencies to ensure this malicious package is not included transitively. Monitor for any signs of compromise related to this package and consider network controls to block communication to the indicated attacker domain. Patch status is not yet confirmed — check the vendor advisory or trusted sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13889
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b2ebf8831d539cdb6f8
Added to database: 08/12/2026, 16:11:26 UTC
Last enriched: 08/12/2026, 16:23:20 UTC
Last updated: 08/12/2026, 16:23:20 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.