LWA-2026-7181 confirmed malware

@adominadmininstr/fmt-date-helper@1.0.0

Malicious code in @adominadmininstr/fmt-date-helper (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1615 · Group Policy DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

@adominadmininstr/fmt-date-helper@1.0.0 is a trojanized date-formatting utility that exfiltrates environment credentials and probes cloud metadata services on install. The postinstall.js hook collects hostname, username, OS info, container environment details, and the full process list, then probes cloud metadata endpoints at metadata[.]tencentyun[.]com/latest/meta-data/ and 169[.]254[.]169[.]254/latest/meta-data/ for cloud instance credentials. It dumps all environment variables (including CI/CD tokens, cloud API keys, and authentication secrets) and base64-encodes the entire payload into an HTTP GET request to pzs5w7ntzhsnepwk564lyfdci3oucl0a[.]oastify[.]com/z?d=<exfiltrated-data>. The exfiltrated data includes GITHUB_TOKEN, NPM_TOKEN, AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY, OPENAI_API_KEY, ANTHROPIC_API_KEY, STRIPE_SECRET_KEY, SENDGRID_API_KEY, SLACK_TOKEN, TWILIO_AUTH_TOKEN, and other credentials from the build environment.

analyzed by
Leitwacht
first seen
Jul 28, 2026, 09:23 AM
analyzed
Jul 28, 2026, 09:25 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.