Evidence · DiggingBeagle record
n8mare on auth street: supply chain attack targets n8n ecosystem
Endor Labs analysis of malicious n8n community-node packages, including a Google Ads-themed package that retrieved n8n-managed OAuth credentials during workflow execution and exfiltrated them to attacker-controlled infrastructure.
- Published
- Jan 9, 2026
- Source role
- primary disclosure
Evidence record
Endor Labs analysis of malicious n8n community-node packages, including a Google Ads-themed package that retrieved n8n-managed OAuth credentials during workflow execution and exfiltrated them to attacker-controlled infrastructure.
Claim-level citations (4)
- supportsMalicious n8n community nodes exfiltrated stored integration credentials: Endor Labs recommends preferring official built-in nodes, auditing community-package source and metadata before installation, monitoring outbound traffic from n8n and using isolated least-privilege service accounts to reduce the authority and detectability gap available to malicious nodes.
Recommendations and defensive guidance
- supportsMalicious n8n community nodes exfiltrated stored integration credentials: Endor Labs reported that the package n8n-nodes-hfgjf-irtuinvcm-lasdqewriit masqueraded as a Google Ads integration, retrieved the configured Google Ads OAuth credential through n8n during workflow execution, and exfiltrated the credential together with host identifiers to attacker-controlled infrastructure.
Opening summary; Indicators of Compromise Summary; malicious Google Ads node/credential-handling analysis
- supportsMalicious n8n community nodes exfiltrated stored integration credentials: Endor Labs explains that an installed n8n community node becomes trusted code inside the automation runtime, where it can receive decrypted credentials needed for integrations, make arbitrary outbound HTTP requests and access the host environment. The documented malicious Google Ads node combined those legitimate runtime capabilities into a credential-exfiltration path.
Analysis of n8n community-node trust inheritance, runtime credential access, outbound networking and host access
- supportsMalicious n8n community nodes exfiltrated stored integration credentials: Package-registry download counts reported alongside the campaign are distribution telemetry and do not by themselves establish unique installations, workflow executions or credential-theft victims; the cited research establishes malicious package behavior but does not provide a verified victim count.
Malicious-package summary table, download figures, and campaign analysis
Cite this record
DiggingBeagle. “n8mare on auth street: supply chain attack targets n8n ecosystem.” Published Jan 9, 2026. https://diggingbeagle.com/sources/n8mare-on-auth-street-supply-chain-attack-targets-n8n-ecosystem/