Logo
npm

n8n-nodes-pentest-rce@1.0.44

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2026-4617

Ecosystem

npm

Summary

On npm install, the package's postinstall script runs a shell pipeline that reads the Kubernetes service-account token from /var/run/secrets/kubernetes.io/serviceaccount/token (truncated to 200 bytes), the pod namespace file, the first 20 sorted environment variables, and host fingerprinting data (id, hostname, uname -a, ip addr, /etc/os-release, mount, /proc/1/status, /proc/1/cgroup), emitting them between =RCE_START= / =RCE_END= markers. In typical n8n custom-node installation contexts (n8n cloud, CI build pipelines, container-image builds), install-time stdout is captured into build logs accessible to the attacker. The advertised node code in dist/PentestNode.node.js is a no-op (return [this.getInputData()]) and index.js exports {} — the package provides no functional value to a consumer; the install-time shell payload is the entire purpose. The package self-identifies as a 'pentest proof of concept' for RCE in its name and description. The exfiltrated K8s SA token grants API access to the cluster the installer runs in, and the env-var dump commonly contains cloud-provider credentials.

Source: amazon-inspector (2a813bc4a209e75b50151451de1c2a3c4a7e916b181b314416eafc43492b4eb5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.