Threats Tagged 'mal-2026-13885'
View all threats tagged with 'mal-2026-13885'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-13885'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in @years19/n8n-nodes-utils-helper-b (npm) 0 The npm package @years19/n8n-nodes-utils-helper-b version 1.0.0 is a malicious package masquerading as a utility helper for n8n workflow automation. It contains a minimal stub node with no real functionality, serving as a cover for malicious behavior. During installation, it executes a postinstall hook that collects system information (user ID and hostname), downloads a malicious tarball from an external URL with TLS verification disabled, and extracts it into the Python site-packages directory. This allows remote code execution on subsequent Python imports. The package also probes the host for offensive security tools and exfiltrates collected data encoded in base64 to a remote server. This behavior enables attackers to gain persistent code execution and gather reconnaissance data from infected systems. Join the discussion | GCVE Database | 08/12/2026, 15:10:52 UTC Added: 08/12/2026, 16:11:26 UTC |
Showing 1 to 1 of 1 result