Malicious npm packages attempted to infiltrate the n8n ecosystem
Researchers at Endor Labs have reported attempts by threat actors to infiltrate the n8n ecosystem with malicious npm packages. One analysed package masqueraded as a Google Ads integration and induced users to enter OAuth credentials, which were then silently exfiltrated to an attacker-controlled server. The packages observed in the campaign had names beginning with n8n-nodes- followed by random strings. This is not a vulnerability in n8n itself, but an illustration of how the platform can be misused as an attack vector.
What this means for your organisation
Endor Labs notes that n8n is an attractive target because it depends heavily on npm for both core functionality and community-provided extensions, and because community nodes execute with the same level of access as the core platform. Many organisations have adopted automation and integration platforms with broad access to business systems, often without the approval process applied to other software. A single extension then becomes a route straight into those integrations.
Berigo recommends
- Introduce approval for which community nodes and extensions may be installed on automation platforms.
- Review which integrations are already installed and who installed them.
- Grant integrations minimum privilege and use a dedicated service account per integration.
- Rotate credentials that may have been exposed through unverified extensions.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch