LWA-2026-11908 MAL-2026-15974 ↗ confirmed malware

date-fns-formatter@1.3.8

Malicious code in date-fns-formatter (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1027 · Obfuscated Files or InformationT1082 · System Information DiscoveryT1539 · Steal Web Session CookieT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

date-fns-formatter@1.3.8 is a trojanized clone of the legitimate date-fns-formatter package. On require, the obfuscated main module creates a temporary directory, writes an obfuscated payload (main.js) and a VBScript, and writes a package.json declaring dependencies axios, better-sqlite3, node-machine-id, and socket[.]io-client. It then runs `npm install` in that directory and executes the payload both via `node main.js` and via cmd.exe invoking the VBScript (detached, hidden window). The bundled dependency set indicates browser-database harvesting (better-sqlite3), machine fingerprinting (node-machine-id), command-and-control over socket[.]io, and HTTP exfiltration (axios). The payload is obfuscated with a large encoded string array and a custom base64 decoder; no C2 endpoint is visible in the static code.

analyzed by
Leitwacht
first seen
Sep 5, 2026, 11:26 PM
analyzed
Sep 5, 2026, 11:27 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.