string-formatter-pro@1.0.0
Malicious code in string-formatter-pro (npm)
T1059.007 · JavaScriptT1059.004 · Unix ShellT1082 · System Information DiscoveryT1552.005 · Cloud Instance Metadata APIT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
The package's postinstall.js hook runs a shell command that uses curl to scrape cloud instance metadata endpoints (AWS 169[.]254[.]169[.]254, Alibaba Cloud 100[.]100[.]100[.]200 and 169[.]254[.]0[.]23, Tencent Cloud metadata[.]tencentyun[.]com) for IAM credentials, then POSTs the collected data to pwpzhsrbtvmfqrqr7onqcwnrcii960up[.]oastify[.]com via /metadata and /data paths. It also attempts to list /data/ and exfiltrate its contents to the same callback host.
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 01:18 PM
- analyzed
- Jul 16, 2026, 01:18 PM
Related advisories
- ripshakti@80.0.0
- anthropic-internal-tools@1.0.0
- date-format-helper2@1.0.4
- hunsterx-package@7.0.1
- delta-time-32bb@1.0.0
- hex-conv-ae7a@1.0.0
- mypocmaliciouspackage-cursorpt1@4.0.0
- simple-date-formatter-util-11@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.