LWA-2026-5867 MAL-2026-6301 ↗ confirmed malware

date-format-helper2@1.0.4

Malicious code in date-format-helper2 (npm)

T1059.007 · JavaScriptT1552.005 · Cloud Instance Metadata APIT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Combosquat package dated-format-helper2 (typosquatting a date-formatting utility) runs a cloud metadata credential scraper in its postinstall.js lifecycle hook. On npm install, the script probes metadata endpoints for all major cloud providers: AWS (169[.]254[.]169[.]254/latest/meta-data/), GCP (metadata.google.internal/computeMetadata/v1/), Alibaba Cloud (100[.]100[.]100[.]200/latest/meta-data/), Tencent Cloud (metadata[.]tencentyun[.]com/latest/meta-data/), ByteDance/Volcengine (100[.]96[.]0[.]2/latest/meta-data/, metadata[.]bytedance[.]com, metadata[.]volcengine[.]com, metadata[.]volces[.]com), and Kata Containers (169[.]254[.]112[.]1/, /dev/vsock*). All responses — including IAM credential metadata — are exfiltrated as JSON via POST to C2 host 5l8e0e95[.]requestrepo[.]com at endpoints /meta-probe, /meta-detail-keys, /meta-detail-values, /meta-aws-keys, /meta-kata-host, and /meta-vsock. The package index.js is a trivial date formatter serving as a decoy facade.

analyzed by
Leitwacht
first seen
Jun 23, 2026, 10:12 AM
analyzed
Jun 23, 2026, 10:12 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.