@years17/n8n-nodes-utils-helper-b@1.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 1:37 AM UTC
OSV ID
MAL-2026-13871
Ecosystem
npm
Summary
The package runs credential-harvesting recon both from its postinstall script and from its main entry (executed at require time). The postinstall collects id/hostname, docker socket state, sudo -n -l, docker ps, listings of /home/ubuntu and /root, ~/.ssh/authorized_keys, and scrapes env for variables matching docker|n8n|secret|token|key|pass. The main module additionally reads ~/.kube/config, ~/.ssh/authorized_keys, and ~/.config/gcloud/application_default_credentials.json, plus SSH directory listing and crontab. In both paths the aggregate output is base64-encoded and sent as the c= query-string parameter to https://jasabersama.id/portfolio-data.php?k=S7k9xQ2mZj via https.request with rejectUnauthorized:false (TLS verification disabled). The package additionally ships an n8n node (nodes/PwnNode.node.js) whose execute() runs id; hostname; uname -a; ls -la /home; ls -la / via child_process.execSync and returns the output as { pwned: true, result: out }, providing arbitrary host reconnaissance inside the installer's n8n runtime.
Source: amazon-inspector (55dc5bbe5a3b2dfb5bf97920ee68027b585bc2b21f4388e88a25986318754397)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.