LWA-2026-11646 confirmed malware
date-fns-sync@1.0.0
Malicious code in date-fns-sync (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
The postinstall hook runs index.js, which fetches a remote script from hxxps://kongregate-api-config[.]vercel[.]app/ and executes the returned payload via eval() at install time. This is a remote code fetch-and-exec downloader: the package name impersonates the legitimate date-fns library (date-fns-sync).
- analyzed by
- Leitwacht
- first seen
- Aug 26, 2026, 07:35 PM
- analyzed
- Aug 26, 2026, 07:35 PM
Related advisories
- supersignaturenature@1.0.5
- external_deps_enjoyer@1.0.0
- zenntechinc-cli@1.6.4
- hydration-vli-ui@1.0.0
- commonjs-code-token@1.0.0
- chai-plus@6.2.5
- r4wk-book@2.2.2
- chai-as-otc@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.