Threat actors published malicious npm packages masquerading as legitimate n8n community nodes, abusing n8n’s extensibility to steal OAuth tokens and other sensitive credentials from environments that installed the rogue integrations. Reporting identified at least eight fake nodes impersonating popular services (e.g., Google Ads, Stripe, Salesforce), including n8n-nodes-hfgjf-irtuinvcm-lasdqewriit and n8n-nodes-gasdhgfuy-rejerw-ytjsadx, with authors using pseudonymous handles such as kakashi-hatake, zabuza-momochi, dan_even_segler, hezi109, haggags, vietts_code, and diendh. The packages prompted users to authenticate in seemingly legitimate flows and then exfiltrated credentials to attacker-controlled infrastructure; several packages were removed after discovery, while additional related packages from some of the same accounts were still being tracked for potentially similar behavior.
Separately, a government advisory warned of multiple high-severity vulnerabilities in n8n—including CVE-2026-21858 (improper input validation that may enable unauthenticated remote code execution via webhook request parsing and file handling), alongside CVE-2026-21877 and CVE-2025-68613—and provided mitigation and detection guidance for defenders. This vulnerability advisory is distinct from the npm supply-chain campaign (malicious third-party nodes vs. core product flaws), but both issues increase risk for organizations running n8n, particularly self-hosted deployments that may function as centralized stores for OAuth tokens, API keys, and other integration secrets.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers and reporting sources advised organizations to prefer built-in or official integrations, audit and remove suspicious community nodes, monitor outbound traffic from automation hosts, rotate exposed credentials, and restrict privileges with isolated service accounts. Guidance also included disabling community packages on self-hosted n8n instances and upgrading to n8n 1.121.0+ or 2.x.
Endor Labs reported the campaign, describing it as an escalation of supply-chain abuse into workflow automation platforms and warning that n8n community nodes run with full privileges and no sandboxing. The disclosure highlighted the risk that automation platforms act as centralized credential vaults embedded in business workflows.
By the time researchers disclosed the campaign, the known malicious packages had begun to be disabled or removed from npm, but several related packages tied to the same accounts remained available and at least one had been recently updated. This indicated the campaign was ongoing and evolving despite takedown efforts.
Once installed, the rogue nodes presented legitimate-looking authentication flows, captured OAuth tokens and API keys, decrypted stored credentials using n8n's master key, and exfiltrated them to attacker-controlled servers during workflow execution. Reports indicated active exploitation in the wild, including unauthorized access affecting services such as Google Ads, Stripe, and Salesforce.
Threat actors uploaded at least eight malicious npm packages masquerading as legitimate n8n community-node integrations, including a fake Google Ads connector. The packages targeted the n8n workflow automation ecosystem as a software supply-chain attack aimed at stealing credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcerescana.com
Open sourcecsoonline.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.