@years17/n8n-nodes-helper-utils@1.0.1
Malicious code in @years17/n8n-nodes-helper-utils (npm)
Analysis
An n8n community node package that performs host reconnaissance on install and on load. The postinstall hook runs `id` and `hostname` and writes the output to /tmp/pwned.txt. The package's main entry point (index.js) and its bundled "PwnNode" node execute `id; hostname; uname -a; ls -la /home; ls -la /; cat /etc/hostname` and write the collected system/user/directory information to /tmp/n8n_pwned.txt. The recon is local-only (no network exfiltration observed); it collects the current user identity, hostname, OS/kernel version, and filesystem directory listings.
- analyzed by
- Leitwacht
- first seen
- Aug 12, 2026, 10:48 AM
- analyzed
- Aug 12, 2026, 10:48 AM
Related advisories
- kit-map-vim@1.0.0
- velora-kit@12.0.2
- dakumangalsingh@1.0.0
- @dgn-src-click-to-pay-org/srcdcfreleasecert@999.0.1
- developer-dashboard@1.0.2
- passkeys-react@1.0.1
- @openzeppelin-5/contracts@1.0.0
- @openzeppelin-4/contracts@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.