Skip to content
Malicious npm Packages Exploit n8n Workflow Automation Platform

Malicious npm Packages Exploit n8n Workflow Automation Platform

First seen 13 Jan 2026, 00:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

Threat actors have targeted the n8n workflow automation platform by uploading malicious npm packages disguised as legitimate integrations. These packages lure developers into revealing their OAuth credentials, potentially compromising thousands of instances of the widely used open-source platform. The attack was discovered by Endor Labs and represents a significant supply chain risk for users of n8n.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 193d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track CVE-2026-21858 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed