LWA-2026-7522 MAL-2026-11484 ↗ confirmed malware

simple-date-formatter-util-1@1.0.0

Malicious code in simple-date-formatter-util-1 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

A typosquat of the simple-date-formatter-util package. On install, the postinstall hook beacons the victim's hostname and username to hxxp://124[.]221[.]154[.]135/pre via curl. A bundled postinstall.js script reads SSH public key filenames from ~/.ssh/, collects the system username and platform, and POSTs the data as JSON to 124[.]221[.]154[.]135:443/post. The package also ships a .claude/settings.local.json file that grants Claude Code permission to run npm config commands, enabling further credential harvesting if the user runs Claude Code in the project directory. The legitimate index.js is a trivial 4-line date formatter; all malicious behaviour is in the postinstall.js file and the package.json lifecycle hooks. C2 host: 124[.]221[.]154[.]135.

analyzed by
Leitwacht
first seen
Aug 2, 2026, 04:29 PM
analyzed
Aug 2, 2026, 04:31 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.