hacker-news · Crawled Aug 5, 2026
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
2 IoCs 1 CVEs
Read original article ↗
AI Summary
GitGuardian researchers identified 321 exposed and still-valid n8n API tokens in public GitHub commits, enabling unauthorized access to sensitive automation workflows, execution data, and stored credentials. Attackers can exploit these tokens to enumerate users, read or exfiltrate data, use or extract stored credentials (e.g., OpenAI API keys), and map high-risk configurations via the audit endpoint—all without exploiting a software vulnerability. The tokens remain valid due to missing expiration dates and poor credential hygiene, with some instances hosted on managed services like n8n.cloud. Responsible disclosure efforts met limited success, highlighting ongoing exposure risks.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 2 extracted
MITRE ATT&CK TTPs 26 techniques
T1021 Remote Services · Lateral Movement T1046 Network Service Discovery · Discovery T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1069 Permission Groups Discovery · Discovery T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1087 Account Discovery · Discovery T1090 Proxy · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1210 Exploitation of Remote Services · Lateral Movement T1485 Data Destruction · Impact T1530 Data from Cloud Storage · Collection T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access T1583 Acquire Infrastructure · Resource Development T1584 Compromise Infrastructure · Resource Development T1585 Establish Accounts · Resource Development T1586 Compromise Accounts · Resource Development T1587 Develop Capabilities · Resource Development T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development