Malicious code in @years19/n8n-nodes-utils-helper-m (npm)
The npm package @years19/n8n-nodes-utils-helper-m version 1.0.0 contains malicious code that executes during installation. Its postinstall script downloads multiple Python tools from an attacker-controlled server with disabled TLS verification, installs them, and launches Python processes that perform DDoS attacks against a hardcoded target. It also collects system information and exfiltrates it to the attacker, who can write arbitrary base64-decoded content to the local filesystem. The package name suggests legitimate utility functionality, but no such features exist in the code.
AI Analysis
Technical Summary
The malicious npm package @years19/n8n-nodes-utils-helper-m (version 1.0.0) includes a postinstall script that fetches several Python packages (mhddos, PyRoxy, impacket, multidict) from a remote server over HTTPS with TLS verification disabled (rejectUnauthorized:false). These packages are extracted into temporary directories and the user's Python site-packages. The script then launches three persistent Python3 processes that direct traffic at a hardcoded IP address, effectively turning the host into a DDoS bot. Additionally, the script executes system commands ('id' and 'hostname'), base64-encodes their output, and sends it as a query parameter to an attacker-controlled URL. The attacker can also write arbitrary base64-decoded data to a file on the victim's system via a crafted URL parameter. Despite the package's name implying it is an n8n-nodes utility, it contains no legitimate functionality and is purely malicious.
Potential Impact
Hosts that install this package are compromised by running unauthorized Python processes that participate in DDoS attacks against a fixed target, potentially implicating the victim in malicious network activity. The attacker gains system information and can write arbitrary files to the victim's filesystem, which may facilitate further compromise or persistence. This undermines system integrity and confidentiality.
Mitigation Recommendations
No official patch or remediation is currently documented for this package. Users should avoid installing @years19/n8n-nodes-utils-helper-m version 1.0.0. Remove the package and any related Python processes if already installed. Monitor systems for unexpected Python processes and network traffic to the specified attacker domains or IP addresses. Verify package authenticity before installation and prefer trusted sources. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Malicious code in @years19/n8n-nodes-utils-helper-m (npm)
Description
The npm package @years19/n8n-nodes-utils-helper-m version 1.0.0 contains malicious code that executes during installation. Its postinstall script downloads multiple Python tools from an attacker-controlled server with disabled TLS verification, installs them, and launches Python processes that perform DDoS attacks against a hardcoded target. It also collects system information and exfiltrates it to the attacker, who can write arbitrary base64-decoded content to the local filesystem. The package name suggests legitimate utility functionality, but no such features exist in the code.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The malicious npm package @years19/n8n-nodes-utils-helper-m (version 1.0.0) includes a postinstall script that fetches several Python packages (mhddos, PyRoxy, impacket, multidict) from a remote server over HTTPS with TLS verification disabled (rejectUnauthorized:false). These packages are extracted into temporary directories and the user's Python site-packages. The script then launches three persistent Python3 processes that direct traffic at a hardcoded IP address, effectively turning the host into a DDoS bot. Additionally, the script executes system commands ('id' and 'hostname'), base64-encodes their output, and sends it as a query parameter to an attacker-controlled URL. The attacker can also write arbitrary base64-decoded data to a file on the victim's system via a crafted URL parameter. Despite the package's name implying it is an n8n-nodes utility, it contains no legitimate functionality and is purely malicious.
Potential Impact
Hosts that install this package are compromised by running unauthorized Python processes that participate in DDoS attacks against a fixed target, potentially implicating the victim in malicious network activity. The attacker gains system information and can write arbitrary files to the victim's filesystem, which may facilitate further compromise or persistence. This undermines system integrity and confidentiality.
Mitigation Recommendations
No official patch or remediation is currently documented for this package. Users should avoid installing @years19/n8n-nodes-utils-helper-m version 1.0.0. Remove the package and any related Python processes if already installed. Monitor systems for unexpected Python processes and network traffic to the specified attacker domains or IP addresses. Verify package authenticity before installation and prefer trusted sources. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13896
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b2fbf8831d539cdb782
Added to database: 08/12/2026, 16:11:27 UTC
Last enriched: 08/12/2026, 16:26:56 UTC
Last updated: 08/12/2026, 16:26:56 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.