simple-date-formatter-util-2@1.0.0
Malicious code in simple-date-formatter-util-2 (npm)
Analysis
The package name combosquats a simple date-formatting utility but ships a malicious postinstall hook and a bundled postinstall.js. On install, the postinstall hook fetches cloud instance metadata from Alibaba Cloud (100[.]100[.]100[.]200), AWS (169[.]254[.]169[.]254), and Tencent Cloud (metadata[.]tencentyun[.]com, 169[.]254[.]0[.]23) metadata endpoints, saves the results to /tmp/, and exfiltrates them via HTTP POST to ycrqyyjhwepdmhjifyccxss1hrks8lcd2[.]oast[.]fun/metadata. It also POSTs a directory listing of /data/ to ycrqyyjhwepdmhjifyccxss1hrks8lcd2[.]oast[.]fun/data. Separately, postinstall.js reads SSH public keys from ~/.ssh/, collects the system username and platform, and POSTs them to 124[.]221[.]154[.]135:443/post. A .claude/settings.local.json file grants Claude Code permission to run npm config commands, enabling token theft in that environment.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 04:42 PM
- analyzed
- Aug 2, 2026, 04:43 PM
Related advisories
- streak-metrics-math@1.0.1
- json-to-table-util@1.0.0
- api-node-sdk@2.1.6
- app-svm-layer@2.1.6
- @daylightqc/date-fmt-lite@1.1.2
- habingeer@2.1.6
- application-util@2.1.6
- solana-key-utils@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.