Malicious code in @years19/n8n-nodes-utils-helper-j (npm)
The npm package @years19/n8n-nodes-utils-helper-j version 1.0.0 contains malicious code that activates during installation or import. It downloads multiple tarballs from an attacker-controlled server with disabled TLS verification, extracts them, and launches Python processes to conduct a DDoS attack against a hardcoded IP address. Additionally, it collects system information and attack logs, encoding and sending them to the attacker. This behavior effectively turns the host into a bot for DDoS attacks and leaks host identity information.
AI Analysis
Technical Summary
The malicious npm package @years19/n8n-nodes-utils-helper-j (version 1.0.0) executes payload code both on npm install and when required. It fetches multiple malicious tarballs from https://jasabersama.id over TLS with certificate verification disabled, extracts them to /tmp and the user's site-packages, and spawns Python3 processes that flood a hardcoded target IP (103.118.252.21) with UDP, TCP, and HTTP traffic, performing a DDoS attack. Concurrently, it collects system identity data (output of 'id' and 'hostname'), dependency status, and attack logs, base64-encodes this data, and sends it as a query parameter to the attacker’s server. The disabling of TLS verification makes the transport resistant to certificate substitution attacks. This package effectively compromises the host by turning it into a DDoS bot and leaking sensitive host information.
Potential Impact
Installing or importing this package results in the host machine being co-opted into a DDoS botnet, launching attacks against a specified target IP address. It also leaks sensitive host information such as user identity and hostname to the attacker. This compromises the confidentiality and availability of the affected system and potentially contributes to external denial-of-service attacks.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately uninstall the package @years19/n8n-nodes-utils-helper-j version 1.0.0 if installed. Avoid installing or importing this package from untrusted sources. Monitor for any unauthorized network traffic to the IP 103.118.252.21 or connections to jasabersama.id. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Malicious code in @years19/n8n-nodes-utils-helper-j (npm)
Description
The npm package @years19/n8n-nodes-utils-helper-j version 1.0.0 contains malicious code that activates during installation or import. It downloads multiple tarballs from an attacker-controlled server with disabled TLS verification, extracts them, and launches Python processes to conduct a DDoS attack against a hardcoded IP address. Additionally, it collects system information and attack logs, encoding and sending them to the attacker. This behavior effectively turns the host into a bot for DDoS attacks and leaks host identity information.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The malicious npm package @years19/n8n-nodes-utils-helper-j (version 1.0.0) executes payload code both on npm install and when required. It fetches multiple malicious tarballs from https://jasabersama.id over TLS with certificate verification disabled, extracts them to /tmp and the user's site-packages, and spawns Python3 processes that flood a hardcoded target IP (103.118.252.21) with UDP, TCP, and HTTP traffic, performing a DDoS attack. Concurrently, it collects system identity data (output of 'id' and 'hostname'), dependency status, and attack logs, base64-encodes this data, and sends it as a query parameter to the attacker’s server. The disabling of TLS verification makes the transport resistant to certificate substitution attacks. This package effectively compromises the host by turning it into a DDoS bot and leaking sensitive host information.
Potential Impact
Installing or importing this package results in the host machine being co-opted into a DDoS botnet, launching attacks against a specified target IP address. It also leaks sensitive host information such as user identity and hostname to the attacker. This compromises the confidentiality and availability of the affected system and potentially contributes to external denial-of-service attacks.
Defensive Guidance
No official patch or remediation is currently documented. Users should immediately uninstall the package @years19/n8n-nodes-utils-helper-j version 1.0.0 if installed. Avoid installing or importing this package from untrusted sources. Monitor for any unauthorized network traffic to the IP 103.118.252.21 or connections to jasabersama.id. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13893
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b2ebf8831d539cdb751
Added to database: 08/12/2026, 16:11:26 UTC
Last enriched: 08/12/2026, 16:25:58 UTC
Last updated: 08/12/2026, 16:25:58 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.