fmt-util-k7x2@1.0.0
Malicious code in fmt-util-k7x2 (npm)
Analysis
The postinstall hook (setup.js) of this package performs network reconnaissance and exfiltration. On install it probes internal Twilio infrastructure endpoints (www[.]stage[.]twilio[.]com, code[.]hq[.]twilio[.]com, twilio[.]jfrog[.]io, artifacts[.]twilio[.]com) and the AWS EC2 instance metadata service (hxxp://169[.]254[.]169[.]254/latest/meta-data/), then sends the reachability results to the attacker-controlled endpoint hxxp://bintool[.]brkd[.]no/compat-check. The AWS metadata probe indicates attempted harvesting of cloud instance credentials. The package's declared purpose (string formatting utilities) is unrelated to this behaviour.
- analyzed by
- Leitwacht
- first seen
- Aug 12, 2026, 03:51 PM
- analyzed
- Aug 12, 2026, 03:51 PM
Related advisories
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-4@1.0.0
- string-formatter-pro@1.0.0
- ripshakti@80.0.0
- anthropic-internal-tools@1.0.0
- date-format-helper2@1.0.4
- hunsterx-package@7.0.1
- delta-time-32bb@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.