format-helper-lib@1.0.0
Malicious code in format-helper-lib (npm)
Analysis
The package is named and described as a benign date/number formatting helper, but its postinstall hook (install-cb.js) runs a container-escape reconnaissance probe. On install it fingerprints the host and container runtime (hostname, OS release, kernel cmdline, runc/containerd/cri-o/docker versions), enumerates security posture (seccomp, AppArmor, SELinux, process capabilities, UID/GID maps, namespace links, /dev), checks for container runtime sockets, tests NFS root-squash, and probes NFS server ports 111 and 2049 on 10[.]0[.]128[.]136. Collected results are written to NCODE_RUNTIME.txt and NCODE_POC_MARKER.txt in the install directory and its parents.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 04:17 AM
- analyzed
- Aug 7, 2026, 04:19 AM
Related advisories
- wormgpt-cli@1.0.1
- simple-date-formatter-new-8@1.0.0
- simple-date-formatter-new-6@1.0.0
- simple-date-formatter-new-5@1.0.0
- n8n-nodes-http-probe@1.0.0
- n8n-nodes-probe@1.0.0
- n8n-nodes-api-finder@1.0.0
- n8n-nodes-port-scanner@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.