simple-date-formatter-util-4@1.0.0
Malicious code in simple-date-formatter-util-4 (npm)
Analysis
The package is a trojanized date-formatting utility. On install, the postinstall hook scrapes cloud instance metadata from AWS (169[.]254[.]169[.]254), Alibaba Cloud (100[.]100[.]100[.]200), and Tencent Cloud (metadata[.]tencentyun[.]com, 169[.]254[.]0[.]23) endpoints, fetches IAM security credentials, and exfiltrates the collected data via HTTP POST to ycrqyyjhwepdmhjifyccxss1hrks8lcd2[.]oast[.]fun/metadata. It also lists the /data/ directory and exfiltrates that. A bundled postinstall.js file reads ~/.ssh/ public keys and sends them to 124[.]221[.]154[.]135:443. The package's index.js is a benign decoy function. A .claude/settings.local.json file attempts to bypass Claude Code's security sandbox by allowing PowerShell(npm config *) commands.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 01:17 PM
- analyzed
- Aug 3, 2026, 01:18 PM
Related advisories
- string-formatter-pro@1.0.0
- ripshakti@80.0.0
- anthropic-internal-tools@1.0.0
- date-format-helper2@1.0.4
- hunsterx-package@7.0.1
- delta-time-32bb@1.0.0
- hex-conv-ae7a@1.0.0
- mypocmaliciouspackage-cursorpt1@4.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.