simple-date-formatter-util-1@1.0.0
Malicious code in simple-date-formatter-util-1 (npm)
Analysis
A typosquat of the simple-date-formatter-util package. On install, the postinstall hook beacons the victim's hostname and username to hxxp://124[.]221[.]154[.]135/pre via curl. A bundled postinstall.js script reads SSH public key filenames from ~/.ssh/, collects the system username and platform, and POSTs the data as JSON to 124[.]221[.]154[.]135:443/post. The package also ships a .claude/settings.local.json file that grants Claude Code permission to run npm config commands, enabling further credential harvesting if the user runs Claude Code in the project directory. The legitimate index.js is a trivial 4-line date formatter; all malicious behaviour is in the postinstall.js file and the package.json lifecycle hooks. C2 host: 124[.]221[.]154[.]135.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 04:29 PM
- analyzed
- Aug 2, 2026, 04:31 PM
Related advisories
- sui-migration-audit-rules@1.0.0
- akamaijs@1.0.1
- nagixjs@2.1.6
- api-rust-sdk@2.1.6
- app-soda-layer@2.1.6
- vscode-designer-14@14.0.1
- messenger-style@1.0.1
- page-navigation@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.