LWA-2026-7621 MAL-2026-12205 ↗ confirmed malware

simple-date-formatter-util-4@1.0.0

Malicious code in simple-date-formatter-util-4 (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.005 · Cloud Instance Metadata APIT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package is a trojanized date-formatting utility. On install, the postinstall hook scrapes cloud instance metadata from AWS (169[.]254[.]169[.]254), Alibaba Cloud (100[.]100[.]100[.]200), and Tencent Cloud (metadata[.]tencentyun[.]com, 169[.]254[.]0[.]23) endpoints, fetches IAM security credentials, and exfiltrates the collected data via HTTP POST to ycrqyyjhwepdmhjifyccxss1hrks8lcd2[.]oast[.]fun/metadata. It also lists the /data/ directory and exfiltrates that. A bundled postinstall.js file reads ~/.ssh/ public keys and sends them to 124[.]221[.]154[.]135:443. The package's index.js is a benign decoy function. A .claude/settings.local.json file attempts to bypass Claude Code's security sandbox by allowing PowerShell(npm config *) commands.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 01:17 PM
analyzed
Aug 3, 2026, 01:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.