simple-date-formatter-new-12@1.0.0
Malicious code in simple-date-formatter-new-12 (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel
Analysis
The package's postinstall hook runs at install time: it fetches content from hxxp://bsrc-ssrf[.]n[.]baidu-int[.]com/6395292252 into /tmp/bsrc.txt, then POSTs that content to the attacker-controlled interaction-capture host hxxp://pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo[.]oast[.]fun/bsrc. This exfiltrates the fetched data to an external collaborator endpoint on every install. The package name is a combosquat of the legitimate simple-date-formatter package.
- analyzed by
- Leitwacht
- first seen
- Sep 24, 2026, 06:10 AM
- analyzed
- Sep 24, 2026, 06:13 AM
Related advisories
- simple-date-formatter-new-11@1.0.0
- eslint-config-compact-base@1.0.0
- @memtensor/memos-cloud-openclaw-plugin@0.1.23
- efhthrthrthregerht@99.9.9
- faceplate-docs@99.9.9
- eslint-plugin-i18n-shreddit@99.9.9
- @tvg-mar/utils@9.9.10
- @tvg-mar/promos-gtm@9.9.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.