simple-date-formatter-util-5@1.0.0
Malicious code in simple-date-formatter-util-5 (npm)
Analysis
The postinstall hook fetches cloud instance metadata from Alibaba Cloud (100[.]100[.]100[.]200/latest/meta-data/), AWS (169[.]254[.]169[.]254/latest/meta-data/), and Tencent Cloud (metadata[.]tencentyun[.]com/latest/meta-data/, 169[.]254[.]0[.]23/latest/meta-data/), writes the results to /tmp, then POSTs all collected metadata to ycrqyyjhwepdmhjifyccxss1hrks8lcd2[.]oast[.]fun/metadata. It also lists the /data/ directory and exfiltrates it to the same oast[.]fun host. The hook then retrieves the AWS IAM role name from 169[.]254[.]169[.]254/latest/meta-data/iam/security-credentials/, fetches the role's temporary security credentials, and pipes them to safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/metadata. A bundled postinstall.js file steals SSH private keys from ~/.ssh/ and sends them to 124[.]221[.]154[.]135:443. A .claude/settings.local.json file grants Claude Code permission to run npm config commands, enabling theft of npm authentication tokens.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 01:25 PM
- analyzed
- Aug 3, 2026, 01:26 PM
Related advisories
- mcp-dev-toolkit@1.5.0
- @across-toolkit/eslint-config@99.0.1
- antsrcsrctest@1.0.0
- hello244b@1.0.0
- stream-read-35cf@1.0.0
- buffer-wrap-67d7@1.0.0
- textdecode@1.2.7
- simple-date-formatter-new-5@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.