Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

n8n-nodes-security-test-pocnpm

n8n-nodes-security-test-poc is a confirmed malicious npm package (MAL-2026-6071) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.1, 1.0.2, 1.0.3…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in n8n-nodes-security-test-poc (npm)

MAL-2026-6071
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall n8n-nodes-security-test-poc

What this malware does

Package presents as an n8n community node but is an attack artifact. The node's execute() in dist/SecurityTestNode.node.js queries AWS IMDSv1/v2 (http://169.254.169.254/latest/meta-data/iam/security-credentials/) and ECS metadata (169.254.170.2) for IAM role credentials, then iterates process.env to harvest every key matching /AWS|AMAZON|ECS|ECR/i, returning all of it in the node's workflow output. Any installer who adds this node to a workflow on an EC2/ECS host leaks the host IAM role's STS credentials and AWS env vars to the workflow output (which is typically persisted/logged) — direct AWS account compromise. The tarball additionally ships preinstall.js, which runs id && hostname && whoami && uname -a && cat /etc/os-release, writes /tmp/n8n-rce-proof.txt, and POSTs the recon output to https://worker.n8n-prod.schibsted.com/rest/variables (with rejectUnauthorized:false) and to 127.0.0.1:5678/rest/variables, using a hardcoded n8n-auth JWT cookie belonging to a third-party org's n8n deployment. package.json does not declare a preinstall lifecycle hook, so the recon payload does not auto-fire on npm install, but the file is bundled as a ready-to-run RCE proof and the JWT is redistributed to anyone who installs the package. The combination of (a) credential-harvest node code reachable on first workflow execution, (b) shipped exfiltration payload with hardcoded victim infrastructure, and (c) redistribution of a third-party auth token makes this an attack artifact regardless of the author's stated PoC framing.

Malicious versions

5 flagged
1.0.11.0.21.0.31.0.41.0.5

Indicators of compromise (SHA-256)

19c5e4a1ba8ae03bc1a47eeb38afb3e2834c395406239daa4f4bd8ac40a49019
fa97d4701c29ef5305fa5b553ab560abd6db6cc33b72f99dc11621997b668f32
55d0c9d23874a3ab1884195d5b6d7245520d4e67878bdf19cc5e1a5c2daea60c
5aeb082546125cdff5d484ca56648143c4e1e173d261f93efff837cfa2d45487
eece457251c8eef166dc093ef5c963ec0d1104d7ca1c7726a98948bc514777ae

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for n8n-nodes-security-test-poc (5 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging n8n-nodes-security-test-poc across your stack and pipelines.

  2. If you installed it — respond

    n8n-nodes-security-test-poc is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If n8n-nodes-security-test-poc was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks n8n-nodes-security-test-poc before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. n8n-nodes-security-test-poc on npm has been identified as a malicious package (versions 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-006917IN-MAL-2026-006918IN-MAL-2026-006914IN-MAL-2026-006916IN-MAL-2026-006915

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks n8n-nodes-security-test-poc-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

n8n-nodes-security-test-poc (npm) malicious package — MAL-2026-6071 | O3 Security