meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, January 13th, 2026: n8n got npm’ed; Gogs exploit; telegram proxy links

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 13 January 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, January 13th, 2026: n8n got npm’ed; Gogs exploit; telegram proxy links

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, January 13th,

0:07.7

2006 edition of the Sands and United Storm Centers, Stormcast.

0:12.6

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.7

And this episode is brought to by the Sands EDU Graduate Certificate Program in Cyber Security Leadership.

0:25.1

Well, and let's start with N8N again.

0:28.1

It's in the news again and not in a good way,

0:31.4

but this time it's not really N8N's fault of what's happening here.

0:36.1

It's a standard NPM supply chain issue. There were a number

0:40.4

of malicious NPM libraries released that in this case actually didn't sort of do the usual

0:47.6

of executing malicious code, the developer system. Instead, they just were into stealing credentials. So the way these particular

0:56.8

packages worked was that they claimed to be like license validators and such for N8N. And so far,

1:03.0

it may be plausible that as you're running the tool created with these packages, it will ask you

1:10.2

to basically add Oath credentials for N8N

1:14.2

for the tool to work,

1:16.6

while these OOF credentials were then exfiltrated and abused by the attacker.

1:22.7

So one of those, I guess,

1:25.7

Oath fishing kind of incidents combined with the NPM supply chain issue.

1:32.7

Again, not really a problem with anything that N8N did.

1:37.7

Nothing really they could fix.

1:39.6

It's just up to NPM to get their act together and kick those packages out.

1:45.6

Luckily, they weren't super popular, in particular, actually I think the wotset were a little bit

1:50.6

better named.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.