Case · DiggingBeagle record

Malicious n8n community nodes exfiltrated stored integration credentials

n8mare is a malicious-extension incident, not a vulnerability in n8n's own code. Endor Labs documented npm community-node packages masquerading as useful integrations; the Google Ads-themed node used the normal n8n credential interface during workflow execution to obtain the configured OAuth material and sent it with host identifiers to attacker-controlled infrastructure. The causal boundary is inherited runtime authority: once an unverified community node is installed, its code executes where legitimate integrations may receive decrypted credentials and where outbound networking is normal. Public package-download telemetry does not establish unique installations, execution or victims, and the cited research does not quantify downstream abuse of stolen credentials.

Assessment profile

Assessment method
Setting
production
Exploitation
observed live
Evidence
Grade B
Remediation
mitigation available
Basis and provenance

The malicious package code and credential-exfiltration mechanism were characterized in a live package campaign, and n8n's own documentation corroborates the community-node trust boundary. Verified victim count and downstream credential abuse are not established, so impact is left unbanded.

Assessed Oct 5, 2026 using diggingbeagle.assessment/1.

Timeline

  1. Jan 9, 2026
    disclosure

    Endor Labs disclosed malicious n8n community nodes

    The initial report documented credential-stealing community-node packages, including the Google Ads-themed exfiltration path.

  2. Jan 13, 2026
    Event type unspecified

    Endor Labs updated the campaign report

    The source was updated as additional malicious-package activity was identified; the update did not convert registry distribution figures into a verified victim count.

Claims & evidence

CLM-N8MARE-MITIGATIONEndor Labs recommends preferring official built-in nodes, auditing community-package source and metadata before installation, monitoring outbound traffic from n8n and using isolated least-privilege service accounts to reduce the authority and detectability gap available to malicious nodes.supported

Basis: reported finding

Link to claim
CLM-N8MARE-CREDENTIAL-EXFILEndor Labs reported that the package n8n-nodes-hfgjf-irtuinvcm-lasdqewriit masqueraded as a Google Ads integration, retrieved the configured Google Ads OAuth credential through n8n during workflow execution, and exfiltrated the credential together with host identifiers to attacker-controlled infrastructure.supported

Basis: reported finding

Link to claim
CLM-N8MARE-RUNTIME-AUTHORITYEndor Labs explains that an installed n8n community node becomes trusted code inside the automation runtime, where it can receive decrypted credentials needed for integrations, make arbitrary outbound HTTP requests and access the host environment. The documented malicious Google Ads node combined those legitimate runtime capabilities into a credential-exfiltration path.supported

Basis: reported finding

Link to claim
CLM-N8MARE-COMMUNITY-AUTHORITYn8n's own documentation warns that community nodes installed from npm are unverified code and can create risks to the host and workflow data, which is the authority boundary the malicious packages abused.supported

Basis: reported finding

Link to claim
CLM-N8MARE-POPULATION-BOUNDARYPackage-registry download counts reported alongside the campaign are distribution telemetry and do not by themselves establish unique installations, workflow executions or credential-theft victims; the cited research establishes malicious package behavior but does not provide a verified victim count.supported

Basis: inference

Link to claim

Sources and citation

Material revision history

  1. Oct 5, 2026 · Published version · first publication · revision 68

Cite this record

DiggingBeagle. “Malicious n8n community nodes exfiltrated stored integration credentials.” Published by DiggingBeagle Oct 5, 2026 · Public disclosure Jan 9, 2026. https://diggingbeagle.com/cases/malicious-n8n-community-nodes-exfiltrated-stored-integration-credentials/

Citation guidance