simple-date-formatter-new-11@1.0.0
Malicious code in simple-date-formatter-new-11 (npm)
Analysis
The package's postinstall hook harvests cloud-provider instance metadata from the Aliyun (100[.]100[.]100[.]200), AWS (169[.]254[.]169[.]254), and Tencent (metadata[.]tencentyun[.]com, 169[.]254[.]0[.]23) metadata endpoints, then POSTs the collected metadata and the output of `ls -la /data/` to the attacker-controlled collaborator host pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo[.]oast[.]fun (paths /metadata and /data). The package otherwise contains only a trivial date-formatter stub; its real purpose is harvesting cloud credentials and environment data on install.
- analyzed by
- Leitwacht
- first seen
- Sep 24, 2026, 05:54 AM
- analyzed
- Sep 24, 2026, 05:55 AM
Related advisories
- homestack-cheer@1.1.9
- pf25262@1.0.0
- pulse-pwn-9f3a2@1.0.0
- feed-widget-helper@1.0.0
- tol8t@14.0.0
- tetotest@14.0.0
- @firelordzuka/pulse-poc@1.0.0
- discord-resolvers@3.4.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.