n8n Atom
World's first n8n client that manage workflow collections inside VSCode/Cursor/Antigravity
- Created
- 6 months ago
- Last commit
- 5 months ago
Security Findings
53Hardcoded C2 with exfil/exec behavior
MaliciousScannerContacts a hardcoded public IP paired with download/eval/sensitive-access/upload
No tagged releases
SuspiciousLineageRepo ships no git tags and no GitHub releases — consumers cannot pin to stable, reviewable versions
Dynamic exec of remote content (VSX)
SuspiciousScannerFetched content reaches a dynamic exec sink in dist/extension.js: Axios
dist/extension.js
Dynamic exec of remote content (VSX)
SuspiciousScannerFetched content reaches a dynamic exec sink in dist/editor-ui/assets/_baseOrderBy-B7m9ONoX.js: Axios
dist/editor-ui/assets/_baseOrderBy-B7m9ONoX.js
Hardcoded secrets/API keys7×
SuspiciousScannerSecret Keyword: apiKe...****
Secret Keyword: chang...****
Secret Keyword: confi...****
Secret Keyword: Forgo...****
Secret Keyword: Chang...****
Secret Keyword: Exter...****
Secret Keyword: exter...****
dist/editor-ui/assets/constants-DU_MZhDK.js
Hardcoded secrets/API keys2×
SuspiciousScannerSecret Keyword: _card...****
Secret Keyword: _apiK...****
dist/editor-ui/assets/SettingsApiView-BtzY6ydl.js
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: apiKe...****
dist/editor-ui/assets/_baseOrderBy-B7m9ONoX.js
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: creat...****
dist/editor-ui/assets/builder.store-ui04SL1k.js
Hardcoded secrets/API keys13×
SuspiciousScannerSecret Keyword: Clien...****
Secret Keyword: Forgo...****
Secret Keyword: API K...****
Secret Keyword: Chang...****
Secret Keyword: Curre...****
Secret Keyword: Passw...****
Secret Keyword: Re-en...****
Secret Keyword: Confi...****
Secret Keyword: New p...****
Secret Keyword: Recov...****
Secret Keyword: Error...****
Secret Keyword: Copy ...****
Secret Keyword: Secre...****
dist/editor-ui/assets/core-CRbPymLT.js
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: _secr...****
dist/editor-ui/assets/index-Cx6Tiuqx.js
Hardcoded secrets/API keys
SuspiciousScannerSecret Keyword: exter...****
dist/editor-ui/assets/router-B4Akwr94.js
Unpinned dependencies
SuspiciousLineage4 unpinned: @n8n/eslint-config, @types/node, eslint, typescript
Suspicious outbound hosts18×
SuspiciousScannerOutbound URLs to non-allowlisted host(s): docs.n8n.io
Outbound URLs to non-allowlisted host(s): community.n8n.io, docs.n8n.io, element-plus.org, feross.org, jmespath.org, moment.github.io, samltest.id, www.g2.com
Outbound URLs to non-allowlisted host(s): ag-grid.com, creators.n8n.io, docs.n8n.io, www.ag-grid.com
Outbound URLs to non-allowlisted host(s): app.infisical.com, element-plus.org, img.youtube.com, www.youtube.com
Outbound URLs to non-allowlisted host(s): docs.n8n.io, moment.github.io
Outbound URLs to non-allowlisted host(s): docs.n8n.io, prettier.io, www.youtube.com
Outbound URLs to non-allowlisted host(s): bit.ly, bugs.chromium.org, circumicons.com, creativecommons.org, css-tricks.com, docs.slatejs.org, drafts.csswg.org, ecma-international.org
Outbound URLs to non-allowlisted host(s): api.ia2s.app, api.n8n.io, api.npms.io, api.open-meteo.com, cdn-rs.n8n.io, docs.n8n.io, feeds.bbci.co.uk, media1.giphy.com
Outbound URLs to non-allowlisted host(s): api.n8n.io, creators.n8n.io, docs.n8n.io, feross.org, json-schema.org, moment.github.io, mths.be, n8n-community.typeform.com
Outbound URLs to non-allowlisted host(s): api.frankfurter.dev, api.open-meteo.com, community.n8n.io, docs.n8n.io, dummyjson.com, evilmartians.com, feeds.bbci.co.uk, hnrss.org
Outbound URLs to non-allowlisted host(s): element-plus.org, sqlite.org, www.youtube-nocookie.com, www.youtube.com
Outbound URLs to non-allowlisted host(s): data.jsdelivr.com, element-plus.org, playgroundcdn.typescriptlang.org
Outbound URLs to non-allowlisted host(s): community.n8n.io, docs.n8n.io, staging-subscription.n8n.io, subscription.n8n.io, www.youtube.com
Outbound URLs to non-allowlisted host(s): sqlite.org
Outbound URLs to non-allowlisted host(s): docs.n8n.io, element-plus.org, evilmartians.com
Outbound URLs to non-allowlisted host(s): 360percents.com, ajv.js.org, api.gumroad.com, bigstickcarpet.com, bit.ly, blog.izs.me, bugs.chromium.org, bugs.webkit.org
Outbound URLs to non-allowlisted host(s): bit.ly, cdn.fakercloud.com, cloudflare-ipfs.com, discord.gg, fb.me, feross.org, git.io, lodash.com
Outbound URLs to non-allowlisted host(s): bugs.chromium.org, circumicons.com, creativecommons.org, discord.gg, electronjs.org, erikflowers.github.io, esbench.com, facebook.com
Workflow makes outbound network call
SuspiciousLineage[.github/workflows/release-publish.yml] curl -u docsWorkflows:${{ secrets.N8N_WEBHOOK_DOCS_PASSWORD }} --request GET 'https://internal.users.n8n.cloud/webhook/t
Workflow exfiltrates secrets to external host
MaliciousLineage[.github/workflows/release-publish.yml] run: curl -u docsWorkflows:${{ secrets.N8N_WEBHOOK_DOCS_PASSWORD }} --request GET 'https://internal.users.n8n.cloud/webh