@daylightqc/date-fmt-lite@1.1.2
Malicious code in @daylightqc/date-fmt-lite (npm)
Analysis
@daylightqc/date-fmt-lite is a combosquat package impersonating a date-formatting utility. On install, postinstall.js beacons the hostname, username, working directory, and Node.js version to hxxp://129[.]204[.]76[.]212:9999/rce-poc. On require, index.js executes a full reconnaissance payload: it reads and exfiltrates SSH private keys (~/.ssh/id_rsa, id_ed25519, id_ecdsa, config, authorized_keys), environment variables (including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and dozens more), /etc/passwd, /etc/shadow, cron jobs, running processes, Kubernetes service account tokens, Docker environment, .npmrc and .env files, and filesystem listings. It probes cloud metadata endpoints across Alibaba Cloud (100[.]100[.]100[.]200), AWS (169[.]254[.]169[.]254), Tencent Cloud (metadata[.]tencentyun[.]com), and GCP (169[.]254[.]169[.]254 with Metadata-Flavor: Google). All collected data is POSTed to hxxp://129[.]204[.]76[.]212:9999/report. The package has no repository URL and provides no genuine date-formatting functionality beyond stubs.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 09:56 AM
- analyzed
- Jul 24, 2026, 09:56 AM
Related advisories
- n8n-nodes-utils-helper@1.0.0
- antsrcsrctest@1.0.0
- delta-time-32bb@1.0.0
- ts-enum-helper@1.0.0
- n8n-nodes-pentest-rce@1.0.1
- format-helper-lib@1.0.0
- simple-date-formatter-new-5@1.0.0
- simple-date-formatter-new-2@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.