date-fns-formatter@1.3.8
Malicious code in date-fns-formatter (npm)
Analysis
date-fns-formatter@1.3.8 is a trojanized clone of the legitimate date-fns-formatter package. On require, the obfuscated main module creates a temporary directory, writes an obfuscated payload (main.js) and a VBScript, and writes a package.json declaring dependencies axios, better-sqlite3, node-machine-id, and socket[.]io-client. It then runs `npm install` in that directory and executes the payload both via `node main.js` and via cmd.exe invoking the VBScript (detached, hidden window). The bundled dependency set indicates browser-database harvesting (better-sqlite3), machine fingerprinting (node-machine-id), command-and-control over socket[.]io, and HTTP exfiltration (axios). The payload is obfuscated with a large encoded string array and a custom base64 decoder; no C2 endpoint is visible in the static code.
- analyzed by
- Leitwacht
- first seen
- Sep 5, 2026, 11:26 PM
- analyzed
- Sep 5, 2026, 11:27 PM
Related advisories
- amprem@1.0.1
- moidevz@1.0.0
- passport811@1.0.0
- gekko-mev-bot@1.0.0
- system-performance-helper@1.0.1
- react-fontawesome-icons@1.0.5
- @salem_jalal/osc-components@1981.17.7
- shadxino@1.0.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.