date-format-helper2@1.0.4
Malicious code in date-format-helper2 (npm)
Analysis
Combosquat package dated-format-helper2 (typosquatting a date-formatting utility) runs a cloud metadata credential scraper in its postinstall.js lifecycle hook. On npm install, the script probes metadata endpoints for all major cloud providers: AWS (169[.]254[.]169[.]254/latest/meta-data/), GCP (metadata.google.internal/computeMetadata/v1/), Alibaba Cloud (100[.]100[.]100[.]200/latest/meta-data/), Tencent Cloud (metadata[.]tencentyun[.]com/latest/meta-data/), ByteDance/Volcengine (100[.]96[.]0[.]2/latest/meta-data/, metadata[.]bytedance[.]com, metadata[.]volcengine[.]com, metadata[.]volces[.]com), and Kata Containers (169[.]254[.]112[.]1/, /dev/vsock*). All responses — including IAM credential metadata — are exfiltrated as JSON via POST to C2 host 5l8e0e95[.]requestrepo[.]com at endpoints /meta-probe, /meta-detail-keys, /meta-detail-values, /meta-aws-keys, /meta-kata-host, and /meta-vsock. The package index.js is a trivial date formatter serving as a decoy facade.
- analyzed by
- Leitwacht
- first seen
- Jun 23, 2026, 10:12 AM
- analyzed
- Jun 23, 2026, 10:12 AM
Related advisories
- hunsterx-package@7.0.1
- delta-time-32bb@1.0.0
- hex-conv-ae7a@1.0.0
- mypocmaliciouspackage-cursorpt1@4.0.0
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-4@1.0.0
- string-formatter-pro@1.0.0
- ripshakti@80.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.