LWA-2026-7646 MAL-2026-12200 ↗ confirmed malware

simple-date-formatter-util-11@1.0.0

Malicious code in simple-date-formatter-util-11 (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1613 · Container and Resource DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1552.005 · Cloud Instance Metadata APIT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package's postinstall hook (defined inline in package.json) runs a comprehensive host-reconnaissance and credential-harvesting script on installation. It collects: user identity, hostname, OS/kernel version, container cgroup info, Docker socket presence, Linux capabilities, Kubernetes service-account tokens, mount table, network interfaces, ARP table, and environment variables matching kube/aws/token/secret/key/pass/role/region/cluster/node/service/container patterns. All collected data is piped via curl POST to hxxp://safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo. The package name is a combosquat of a legitimate utility name with a numeric suffix.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 03:36 PM
analyzed
Aug 3, 2026, 03:37 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.