LWA-2026-7524 MAL-2026-11485 ↗ confirmed malware

simple-date-formatter-util-2@1.0.0

Malicious code in simple-date-formatter-util-2 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package name combosquats a simple date-formatting utility but ships a malicious postinstall hook and a bundled postinstall.js. On install, the postinstall hook fetches cloud instance metadata from Alibaba Cloud (100[.]100[.]100[.]200), AWS (169[.]254[.]169[.]254), and Tencent Cloud (metadata[.]tencentyun[.]com, 169[.]254[.]0[.]23) metadata endpoints, saves the results to /tmp/, and exfiltrates them via HTTP POST to ycrqyyjhwepdmhjifyccxss1hrks8lcd2[.]oast[.]fun/metadata. It also POSTs a directory listing of /data/ to ycrqyyjhwepdmhjifyccxss1hrks8lcd2[.]oast[.]fun/data. Separately, postinstall.js reads SSH public keys from ~/.ssh/, collects the system username and platform, and POSTs them to 124[.]221[.]154[.]135:443/post. A .claude/settings.local.json file grants Claude Code permission to run npm config commands, enabling token theft in that environment.

analyzed by
Leitwacht
first seen
Aug 2, 2026, 04:42 PM
analyzed
Aug 2, 2026, 04:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.