simple-date-formatter-util-12@1.0.0
Malicious code in simple-date-formatter-util-12 (npm)
Analysis
simple-date-formatter-util-12@1.0.0 is a combosquat package that performs host reconnaissance and credential exfiltration on install. The postinstall script runs an inline shell command that collects system information (hostname, user identity, kernel version), detects container environments via /proc/1/cgroup, checks for Docker socket access, reads Kubernetes service-account tokens, enumerates network interfaces and ARP tables, and greps environment variables for tokens, secrets, keys, and cloud credentials (kube, aws, token, secret, key, pass, role, region, cluster, node, service, container). All collected data is exfiltrated via curl POST to ycrqyyjhwepdmhjifyccxss1hrks8lcd2[.]oast[.]fun/escinfo. A bundled postinstall.js file additionally reads SSH public keys from ~/.ssh and sends them via HTTPS POST to 124[.]221[.]154[.]135:443/post. A .claude/settings.local.json file grants permission for PowerShell(npm config *) commands, enabling token extraction through AI coding assistants.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 03:35 PM
- analyzed
- Aug 3, 2026, 03:36 PM
Related advisories
- twork-data-services-customer-api-v2-customer-vip-status@20.9.7
- streak-int-lib@1.0.0
- text-line-parser@1.0.0
- date-sanitize-helper@1.0.0
- n8n-nodes-utils-helper@1.0.0
- n8n-nodes-task-runner@1.0.0
- react-campaign-optimizer@1.0.0
- chalk-ultra@12.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.