INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

n8n API Tokens Leaked Exposing Live Instances to Credential Theft

| 2026-08-05 10:35 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
On August 5, 2026, a cyber operation was conducted where GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits. The attackers demonstrated four techniques to access sensitive data and downstream credentials without exploiting a software vulnerability. This attack affected approximately 896 reachable instances of the platform, with leaked credentials providing authenticated access to around 36% or roughly 26% of all hostnames identified. The operation worked by utilizing documented REST API functionality and standard HTTP requests, requiring no CVE exploitation or specialized tooling. As of March 31, 2026, more than 58% of n8n instances were running a version affected by at least one known security advisory, with over 100,000 instances visible through Shodan.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2025-68613 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
pr•••••.env
n8•••••.cloud
n8•••••.cloud
os•••••.getenv
se•••••.json
se•••••.json
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-68613CVE-2025-68613
Target & Sectors
NORTH_AMERICA NORTH_AMERICA technologytechnology
Incident Timeline
‎February 2025
Threat actors used leaked n8n API tokens to expose live instances to credential theft, demonstrating techniques ranging from passive enumeration to active credential exfiltration.
infrastructure N8N
financial $1,200 $ bounty
‎April 2025
Threat actors exploited leaked n8n API tokens, which were generated without expiration dates or had no "exp" claim, to access live instances and potentially steal credentials.
infrastructure N8N
infrastructure 1.78.0
‎March 11, 2026
Threat actors obtained and exposed leaked n8n API tokens, which provided authenticated access to live instances, allowing for credential theft.
infrastructure N8N
‎2026/08/05
Threat actors used leaked n8n API tokens to access sensitive data and downstream credentials without exploiting a software vulnerability.
infrastructure N8N
data_breach 4,576 unique credentials
infrastructure 1,255 hostnames
infrastructure 5,469 Unique hostnames
Tactical Metrics
Metrics
infrastructure
‎N8N
Affected Product
Metrics
data_breach
4,576
Unique Credentials
Metrics
infrastructure
1,255
Hostnames
Metrics
infrastructure
‎1.78.0
Software Version
Metrics
infrastructure
5,469
Unique Hostnames
Metrics
financial
1,200
$ Bounty
Intelligence Sources