logo

Hackers Infiltrated n8n’s Community Node Ecosystem With a Weaponized npm Package

ID: 07e1b6c9-7e12-5610-8ff2-be0689a268b4

STIX ID: report--07e1b6c9-7e12-5610-8ff2-be0689a268b4

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-12

Date Updated: 2026-04-21

Author: Abinaya

...
...

Attackers distributed malicious npm packages for the n8n community node ecosystem that installed a fake Google Ads integration which tricked users into entering OAuth credentials; the malicious node exfiltrated those credentials to attacker-controlled servers during workflow execution. EndorLabs identified at least eight malicious packages (the primary package had ~3,400 weekly downloads before removal) and warns that n8n community nodes run with high privileges, making supply-chain compromises particularly dangerous; recommended mitigations include preferring official nodes, auditing packages, monitoring outbound traffic, and using least-privilege service accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.