LWA-2026-7645 MAL-2026-12201 ↗ confirmed malware

simple-date-formatter-util-12@1.0.0

Malicious code in simple-date-formatter-util-12 (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1613 · Container and Resource DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1057 · Process Discovery

Analysis

simple-date-formatter-util-12@1.0.0 is a combosquat package that performs host reconnaissance and credential exfiltration on install. The postinstall script runs an inline shell command that collects system information (hostname, user identity, kernel version), detects container environments via /proc/1/cgroup, checks for Docker socket access, reads Kubernetes service-account tokens, enumerates network interfaces and ARP tables, and greps environment variables for tokens, secrets, keys, and cloud credentials (kube, aws, token, secret, key, pass, role, region, cluster, node, service, container). All collected data is exfiltrated via curl POST to ycrqyyjhwepdmhjifyccxss1hrks8lcd2[.]oast[.]fun/escinfo. A bundled postinstall.js file additionally reads SSH public keys from ~/.ssh and sends them via HTTPS POST to 124[.]221[.]154[.]135:443/post. A .claude/settings.local.json file grants permission for PowerShell(npm config *) commands, enabling token extraction through AI coding assistants.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 03:35 PM
analyzed
Aug 3, 2026, 03:36 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.