LWA-2026-11178 confirmed malware

datefmt-util-helper@1.0.0

Malicious code in datefmt-util-helper (npm)

T1059.007 · JavaScriptT1071 · Application Layer Protocol

Analysis

The package's postinstall hook (postinstall.js) opens a reverse shell on install: it connects to 8[.]135[.]48[.]40:4444 and spawns an interactive /bin/bash, using three fallback methods (python3 PTY, python3 subprocess, and a Node net socket). The package otherwise contains only a trivial date-formatting stub; its real behaviour is establishing a remote command shell on the installing machine.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 02:32 PM
analyzed
Aug 13, 2026, 02:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.