Eight illicit npm packages purporting to be integrations to the n8n workflow automation platform have exploited community nodes to compromise developers' OAuth tokens as part of an ongoing supply chain campaign, The Hacker News reports.Installation of an updated iteration of the "n8n-nodes-gg-udhasudsh-hgjkhg-official" package as a community node enables the saving of Google Ads account OAuth tokens to the n8n credential store, with the workflow's execution prompting the exfiltration of stored tokens to a remote server, according to a report from Endor Labs. Only half of the libraries have been removed so far. Such findings emphasize the continued evolution of supply chain threats, with the integration of untrusted workflows increasing the attack surface, according to researchers."There is no sandboxing or isolation between node code and the n8n runtime. Because of this, a single malicious npm package is enough to gain deep visibility into workflows, steal credentials, and communicate externally without raising immediate suspicion. For attackers, the npm supply chain offers a quiet and highly effective entry point into n8n environments," said researchers.
Supply chain, Identity

OAuth credential theft sought by new n8n supply chain intrusion

(Credit: Luciano Luppa – stock.adobe.com)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



