OpenSSF/OSV advisory MAL-2026-16147 confirms this npm version as malicious. On require() of the package, dist/SysDiagNode.node.js runs a deferred bootstrap that enumerates process.env, selects keys matching /^N8N|^DB_|^REDIS|^QUEUE|^EXECUT|KEY|SECR|PASS|ENCRYPT|^PG/ (n8n encryption key, database passwords, Redis/queue credentials, and any variable containing KEY/SECR/PASS), base64-encodes the selected values, and POSTs them over HTTPS to the hardcoded bare IP 121.127.33.228:443 at path...
Source appears to send environment or credential material to an external endpoint.
dist/SysDiagNode.node.jsView on unpkg · L42A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/SysDiagNode.node.jsView on unpkg · L42This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/SysDiagNode.node.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/SysDiagNode.node.jsView on unpkg · L42Package source references dynamic require/import behavior.
dist/SysDiagNode.node.jsView on unpkg · L42This report applies to n8n-nodes-sysdiag@1.0.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source appears to send environment or credential material to an external endpoint.
dist/SysDiagNode.node.jsView on unpkg · L42A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/SysDiagNode.node.jsView on unpkg · L42This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/SysDiagNode.node.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/SysDiagNode.node.jsView on unpkg · L42Package source references dynamic require/import behavior.
dist/SysDiagNode.node.jsView on unpkg · L42