Hackers Infiltrated n8n’s Community Node Ecosystem With a Weaponized npm Package
ID: 07e1b6c9-7e12-5610-8ff2-be0689a268b4
STIX ID: report--07e1b6c9-7e12-5610-8ff2-be0689a268b4
Feed Name: cybersecurityNews.com
Attackers distributed malicious npm packages for the n8n community node ecosystem that installed a fake Google Ads integration which tricked users into entering OAuth credentials; the malicious node exfiltrated those credentials to attacker-controlled servers during workflow execution. EndorLabs identified at least eight malicious packages (the primary package had ~3,400 weekly downloads before removal) and warns that n8n community nodes run with high privileges, making supply-chain compromises particularly dangerous; recommended mitigations include preferring official nodes, auditing packages, monitoring outbound traffic, and using least-privilege service accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
