Ground.News Malicious npm Packages Exploit n8n Workflow Automation Platform
Article Content
Browse articles
Threat actors have targeted the n8n workflow automation platform by uploading malicious npm packages disguised as legitimate integrations. These packages lure developers into revealing their OAuth credentials, potentially compromising thousands of instances of the widely used open-source platform. The attack was discovered by Endor Labs and represents a significant supply chain risk for users of n8n.
Ask AI about this cluster
Answers cite the sources they use
Updated 193d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track CVE-2026-21858 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Red Heron Exploits Gitea RCE Flaw in Multinational Campaign A Chinese-speaking threat actor, tracked as Red Heron, exploited the CVE-2026-60004 remote code execution vulnerability in Gitea, compromising 1,386 instances across seven countries. The campaign involved source-code theft, credential collection, and lateral movement, affecting organizations in Canada, Argentina…