LWA-2026-11178 confirmed malware
datefmt-util-helper@1.0.0
Malicious code in datefmt-util-helper (npm)
T1059.007 · JavaScriptT1071 · Application Layer Protocol
Analysis
The package's postinstall hook (postinstall.js) opens a reverse shell on install: it connects to 8[.]135[.]48[.]40:4444 and spawns an interactive /bin/bash, using three fallback methods (python3 PTY, python3 subprocess, and a Node net socket). The package otherwise contains only a trivial date-formatting stub; its real behaviour is establishing a remote command shell on the installing machine.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 02:32 PM
- analyzed
- Aug 13, 2026, 02:32 PM
Related advisories
- my-auto-follow@1.0.0
- internallib_v756@1.0.7
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
- streak-map-kit@1.0.0
- dolyame-ui-noindex@35.8.1
- ded-pwa-c-boxy-di@35.2.2
- devplatform-spa-errors@35.5.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.