date-fns-lite@1.0.6
Malicious code in date-fns-lite (npm)
Analysis
date-fns-lite is a combosquat of the legitimate date-fns library. On install, its postinstall.js hook performs host reconnaissance and credential theft across both Linux and Windows. On Linux it attempts container escape via /proc/1/root access, Docker socket abuse, cgroup analysis, unshare namespace escape, SUID binary enumeration, and kernel module loading. On Windows it collects system information, Chrome and Edge browser data (bookmarks, history, extensions, login data), network configuration (ipconfig, netstat, arp, route table), desktop and documents file listings, SSH keys, .gitconfig, .npmrc, credential manager output, and environment variables including AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, NPM_TOKEN, and DOCKER_PASSWORD. All collected data is exfiltrated via HTTP POST to 115[.]190[.]124[.]243:9082/callback as JSON. The package's index.js is a decoy date-formatting utility with no relation to the malicious postinstall payload.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 01:16 PM
- analyzed
- Jul 1, 2026, 08:19 PM
Related advisories
- nat-ulid@3.0.2
- check-ulid@3.0.2
- web3-core-utils@4.3.5
- textdecode@1.2.7
- svg2text@3.0.0
- shadcn-ui-autocomplete@3.5.0
- polymarket-gamma-apis@1.4.0
- pocbitbarrontest@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.