simple-date-formatter-util-14@1.0.0
Malicious code in simple-date-formatter-util-14 (npm)
Analysis
The package is a combosquat decoy impersonating a date-formatting utility. On install, the postinstall hook runs a shell script that performs environment reconnaissance: lists the working directory, probes an internal Kubernetes API server (10[.]45[.]196[.]224:6443), reads process namespace information, mountinfo, and process capabilities. All collected data is POSTed to safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo3. A bundled postinstall.js additionally reads SSH public keys from ~/.ssh/*.pub and user information, then sends them to 124[.]221[.]154[.]135:443 via HTTPS POST. The package's index.js is a benign decoy containing a single date-formatting function.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 04:03 PM
- analyzed
- Aug 3, 2026, 04:04 PM
Related advisories
- json-to-table-util@1.0.0
- text-line-parser@1.0.0
- shift-sdk-v5@5.0.1
- simple-date-formatter-util-13@1.0.0
- simple-date-formatter-util-2@1.0.0
- streak-metrics-math@1.0.1
- api-node-sdk@2.1.6
- app-svm-layer@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.