simple-date-formatter-new-13@1.0.0
Malicious code in simple-date-formatter-new-13 (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package runs a malicious postinstall hook on install. It downloads a remote file to /tmp/bsrc.txt and POSTs its contents to the callback host pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo[.]oast[.]fun/bsrc. A bundled postinstall.js script enumerates the user's ~/.ssh directory for public-key filenames, collects the OS username and platform, and exfiltrates this data as JSON to hxxps://124[.]221[.]154[.]135:443/post. The package is a combosquat on the "simple-date-formatter" name.
- analyzed by
- Leitwacht
- first seen
- Sep 24, 2026, 06:14 AM
- analyzed
- Sep 24, 2026, 06:16 AM
Related advisories
- @memtensor/memos-cloud-openclaw-plugin@0.1.23
- @dbbhk/ui-components@99.0.0
- fdhcxvnwhjiofv@1.0.0
- siriusbeyond@1.0.0
- chai-as-viem@1.1.3
- chai-as-indexed@7.2.8
- pflag29424@1.0.0
- pf25133@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.