LWA-2026-7652 MAL-2026-12203 ↗ confirmed malware

simple-date-formatter-util-14@1.0.0

Malicious code in simple-date-formatter-util-14 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1614 · System Location DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web ProtocolsT1005 · Data from Local System

Analysis

The package is a combosquat decoy impersonating a date-formatting utility. On install, the postinstall hook runs a shell script that performs environment reconnaissance: lists the working directory, probes an internal Kubernetes API server (10[.]45[.]196[.]224:6443), reads process namespace information, mountinfo, and process capabilities. All collected data is POSTed to safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo3. A bundled postinstall.js additionally reads SSH public keys from ~/.ssh/*.pub and user information, then sends them to 124[.]221[.]154[.]135:443 via HTTPS POST. The package's index.js is a benign decoy containing a single date-formatting function.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 04:03 PM
analyzed
Aug 3, 2026, 04:04 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.