n8n Nodes Compromised by Malicious npm Package
Hackers have compromised n8n nodes by exploiting a weaponized npm package posing as a legitimate Google Ads integration. The malicious package mimicked authentic functionality, tricking developers into entering their OAuth credentials. Once input, the data was exfiltrated to an attacker-controlled server during routine workflow execution. Researchers at EndorLabs uncovered eight malicious packages targeting the automation […]
