simple-date-formatter-util-13@1.0.0
Malicious code in simple-date-formatter-util-13 (npm)
Analysis
The package "simple-date-formatter-util-13" is a combosquat impersonating a date-formatting utility. Its postinstall hook runs a shell command that performs extensive environment reconnaissance: checks for seccomp/NoNewPrivs restrictions, lists /dev entries, probes NFS-mounted directories, probes Kubernetes API servers at 10[.]45[.]196[.]138:6443 and 104[.]16[.]5[.]34:6443, reads /etc/hosts, and checks process capabilities. All collected data is POSTed to the C2 endpoint safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo2. A bundled postinstall.js file additionally reads SSH public keys from ~/.ssh/ and exfiltrates them along with the username and platform to 124[.]221[.]154[.]135:443 via HTTPS POST. A .claude/settings.local.json file grants PowerShell(npm config *) permissions, enabling npm token theft via Claude Code. The main index.js is a 160-byte decoy date formatter.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 03:55 PM
- analyzed
- Aug 3, 2026, 03:56 PM
Related advisories
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-12@1.0.0
- num-format-helper@1.0.0
- chart-data-utils@1.0.0
- @daylightqc/date-fmt-lite@1.1.2
- n8n-nodes-utils-helper@1.0.0
- antsrcsrctest@1.0.0
- delta-time-32bb@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.