LWA-2026-12375 MAL-2026-17158 ↗ confirmed malware

simple-date-formatter-new-11@1.0.0

Malicious code in simple-date-formatter-new-11 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

The package's postinstall hook harvests cloud-provider instance metadata from the Aliyun (100[.]100[.]100[.]200), AWS (169[.]254[.]169[.]254), and Tencent (metadata[.]tencentyun[.]com, 169[.]254[.]0[.]23) metadata endpoints, then POSTs the collected metadata and the output of `ls -la /data/` to the attacker-controlled collaborator host pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo[.]oast[.]fun (paths /metadata and /data). The package otherwise contains only a trivial date-formatter stub; its real purpose is harvesting cloud credentials and environment data on install.

analyzed by
Leitwacht
first seen
Sep 24, 2026, 05:54 AM
analyzed
Sep 24, 2026, 05:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.