LWA-2026-6211 MAL-2026-6722 ↗ confirmed malware

date-fns-lite@1.0.6

Malicious code in date-fns-lite (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1552.001 · Credentials In FilesT1555.003 · Credentials from Web BrowsersT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1611 · Escape to Host

Analysis

date-fns-lite is a combosquat of the legitimate date-fns library. On install, its postinstall.js hook performs host reconnaissance and credential theft across both Linux and Windows. On Linux it attempts container escape via /proc/1/root access, Docker socket abuse, cgroup analysis, unshare namespace escape, SUID binary enumeration, and kernel module loading. On Windows it collects system information, Chrome and Edge browser data (bookmarks, history, extensions, login data), network configuration (ipconfig, netstat, arp, route table), desktop and documents file listings, SSH keys, .gitconfig, .npmrc, credential manager output, and environment variables including AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, NPM_TOKEN, and DOCKER_PASSWORD. All collected data is exfiltrated via HTTP POST to 115[.]190[.]124[.]243:9082/callback as JSON. The package's index.js is a decoy date-formatting utility with no relation to the malicious postinstall payload.

analyzed by
Leitwacht
first seen
Jul 1, 2026, 01:16 PM
analyzed
Jul 1, 2026, 08:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.