n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens

In order to acquire developers’ OAuth credentials, threat actors have been seen uploading eight packages to the npm registry under the guise of integrations that target the n8n workflow automation platform.

One such package, called “n8n-nodes-hfgjf-irtuinvcm-lasdqewriit,” imitates a Google Ads integration and asks users to connect their advertising account in a way that looks authentic before stealing OAuth credentials to servers that are controlled by the attackers.

According to a report released last week by Endor Labs, “the attack represents a new escalation in supply chain threats.” This campaign took advantage of workflow automation platforms that function as centralized credential vaults, storing OAuth tokens, API keys, and sensitive credentials for dozens of integrated services like Google Ads, Stripe, and Salesforce in one place, in contrast to traditional npm malware, which frequently targets developer credentials read more about n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *