simple-date-formatter-util-7@1.0.0
Malicious code in simple-date-formatter-util-7 (npm)
Analysis
Combosquat package impersonating a date-formatting utility. On install, the postinstall hook executes a reverse shell connecting to 124[.]221[.]154[.]135:4444 via /dev/tcp. Additionally, postinstall.js reads the victim's ~/.ssh/*.pub public keys and system information (username, platform) and exfiltrates them via HTTPS POST to hxxps://124[.]221[.]154[.]135/post. The package also ships a .claude/settings.local.json file that grants permission for PowerShell(npm config *) commands, enabling npm token theft via Claude Code. The main index.js is a benign decoy function.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 02:42 PM
- analyzed
- Aug 3, 2026, 02:43 PM
Related advisories
- simple-date-formatter-util-6@1.0.0
- simple-date-formatter-util-5@1.0.0
- simple-date-formatter-util-4@1.0.0
- tinkoff-boxy-mobile-documents@20.1.7
- statist-browser-typed-client-risktech.uwfrontantifraud.events@20.1.5
- nxify-unic@20.3.2
- statist-browser-typed-client-social.shorts.editor@20.7.1
- pfp-forms-sme-sitebuilder@20.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.