n8n Supply Chain Attack Exploits Community Nodes to Steal OAuth Tokens
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Threat actors have uploaded eight malicious packages to the npm registry, specifically designed to target the n8n workflow automation platform. These packages, including ‘n8n-nodes-hfgjf-irtuinvcm-lasdqewriit’ and ‘n8n-nodes-gasdhgfuy-rejerw-ytjsadx,’ have been used to siphon OAuth credentials from users. The attack was discovered on January 12, 2026, and represents a significant escalation in supply chain threats.
The malicious packages masquerade as legitimate integrations, prompting users to link their accounts. Once installed, they save OAuth tokens in an encrypted format and exfiltrate them to remote servers when workflows are executed. This approach takes advantage of n8n’s architecture, which acts as a centralized credential vault for multiple services.
Among the identified packages, ‘n8n-nodes-gasdhgfuy-rejerw-ytjsadx’ had the highest number of downloads at 8,385, followed by ‘n8n-nodes-danev’ with 5,525 downloads. The attack underscores the risks associated with integrating untrusted workflows, as these packages can access sensitive credentials without raising immediate suspicion.
N8n has advised users to disable community nodes on self-hosted instances to mitigate risks, as these nodes operate with the same access level as n8n itself. The lack of sandboxing means that malicious packages can gain deep visibility into workflows and steal credentials.
This incident serves as a warning for developers to audit packages before installation and to scrutinize package metadata for anomalies. The ongoing nature of this campaign, evidenced by the release of updated packages, suggests that attackers are actively seeking to exploit vulnerabilities in the n8n ecosystem.
Why This Matters for Your Security
The n8n supply chain attack highlights the importance of vigilance when using community integrations. Developers should be aware that a single malicious package can lead to significant credential theft and unauthorized access to sensitive data.
Organizations must implement strict package auditing procedures and consider limiting the use of community nodes to trusted sources. Monitoring for unusual activity and regularly reviewing access logs can help identify potential breaches early.
As this attack shows, the npm supply chain can serve as a quiet entry point for attackers, making it crucial for users to remain proactive in their security practices.
Key Takeaways
- Audit all npm packages before installation to ensure they are from trusted sources.
- Disable community nodes in self-hosted n8n instances to reduce the risk of malicious actions.
- Regularly review access logs for unusual activity that may indicate credential theft.
- Monitor for updates or changes to community packages that could signal ongoing attacks.
- Educate team members about the risks associated with integrating untrusted workflows.
Key Terms & Concepts
- OAuth: In this article, OAuth refers to an open standard for access delegation commonly used for token-based authentication.
- npm: In this article, npm refers to a package manager for JavaScript that allows developers to share and reuse code.
- n8n: In this article, n8n is a workflow automation platform that enables users to integrate various services and automate tasks.
- Supply Chain Attack: In this article, a supply chain attack refers to a cyberattack that targets the supply chain of software to compromise the integrity of the software.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.