LWA-2026-7651 MAL-2026-12202 ↗ confirmed malware

simple-date-formatter-util-13@1.0.0

Malicious code in simple-date-formatter-util-13 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1613 · Container and Resource DiscoveryT1005 · Data from Local SystemT1552.004 · Private KeysT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package "simple-date-formatter-util-13" is a combosquat impersonating a date-formatting utility. Its postinstall hook runs a shell command that performs extensive environment reconnaissance: checks for seccomp/NoNewPrivs restrictions, lists /dev entries, probes NFS-mounted directories, probes Kubernetes API servers at 10[.]45[.]196[.]138:6443 and 104[.]16[.]5[.]34:6443, reads /etc/hosts, and checks process capabilities. All collected data is POSTed to the C2 endpoint safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo2. A bundled postinstall.js file additionally reads SSH public keys from ~/.ssh/ and exfiltrates them along with the username and platform to 124[.]221[.]154[.]135:443 via HTTPS POST. A .claude/settings.local.json file grants PowerShell(npm config *) permissions, enabling npm token theft via Claude Code. The main index.js is a 160-byte decoy date formatter.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 03:55 PM
analyzed
Aug 3, 2026, 03:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.