LWA-2026-7085 MAL-2026-11041 ↗ confirmed malware

@daylightqc/date-fmt-lite@1.1.2

Malicious code in @daylightqc/date-fmt-lite (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1005 · Data from Local SystemT1552.001 · Credentials In FilesT1552.004 · Private KeysT1613 · Container and Resource DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

@daylightqc/date-fmt-lite is a combosquat package impersonating a date-formatting utility. On install, postinstall.js beacons the hostname, username, working directory, and Node.js version to hxxp://129[.]204[.]76[.]212:9999/rce-poc. On require, index.js executes a full reconnaissance payload: it reads and exfiltrates SSH private keys (~/.ssh/id_rsa, id_ed25519, id_ecdsa, config, authorized_keys), environment variables (including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and dozens more), /etc/passwd, /etc/shadow, cron jobs, running processes, Kubernetes service account tokens, Docker environment, .npmrc and .env files, and filesystem listings. It probes cloud metadata endpoints across Alibaba Cloud (100[.]100[.]100[.]200), AWS (169[.]254[.]169[.]254), Tencent Cloud (metadata[.]tencentyun[.]com), and GCP (169[.]254[.]169[.]254 with Metadata-Flavor: Google). All collected data is POSTed to hxxp://129[.]204[.]76[.]212:9999/report. The package has no repository URL and provides no genuine date-formatting functionality beyond stubs.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 09:56 AM
analyzed
Jul 24, 2026, 09:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.