@adominadmininstr/fmt-date-helper@1.0.0
Malicious code in @adominadmininstr/fmt-date-helper (npm)
Analysis
@adominadmininstr/fmt-date-helper@1.0.0 is a trojanized date-formatting utility that exfiltrates environment credentials and probes cloud metadata services on install. The postinstall.js hook collects hostname, username, OS info, container environment details, and the full process list, then probes cloud metadata endpoints at metadata[.]tencentyun[.]com/latest/meta-data/ and 169[.]254[.]169[.]254/latest/meta-data/ for cloud instance credentials. It dumps all environment variables (including CI/CD tokens, cloud API keys, and authentication secrets) and base64-encodes the entire payload into an HTTP GET request to pzs5w7ntzhsnepwk564lyfdci3oucl0a[.]oastify[.]com/z?d=<exfiltrated-data>. The exfiltrated data includes GITHUB_TOKEN, NPM_TOKEN, AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY, OPENAI_API_KEY, ANTHROPIC_API_KEY, STRIPE_SECRET_KEY, SENDGRID_API_KEY, SLACK_TOKEN, TWILIO_AUTH_TOKEN, and other credentials from the build environment.
- analyzed by
- Leitwacht
- first seen
- Jul 28, 2026, 09:23 AM
- analyzed
- Jul 28, 2026, 09:25 AM
Related advisories
- @adominadmininstr/date-util-helper@1.0.0
- array-sort-helper@1.0.0
- style-class-utils@1.0.0
- date-sanitize-helper@1.0.0
- data-format-helper@1.0.1
- color-convert-helper@1.0.0
- react-campaign-optimizer@1.0.0
- simple-date-formatter-new-7@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.