LWA-2026-7655 MAL-2026-11502 ↗ confirmed malware

simple-date-formatter-new-1@1.0.0

Malicious code in simple-date-formatter-new-1 (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.007 · JavaScriptT1082 · System Information DiscoveryT1613 · Container and Resource DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

simple-date-formatter-new-1@1.0.0 is a combosquat package impersonating date-formatting utilities. Its postinstall script performs container escape (creates a block device node and mounts the host root filesystem), then exfiltrates Kubernetes service-account tokens, pod listings, cluster configuration, CI agent directory contents, and the ARP table via a curl POST to safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo4. A bundled postinstall.js additionally steals SSH private keys and exfiltrates them to 124[.]221[.]154[.]135:443.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 04:25 PM
analyzed
Aug 3, 2026, 04:26 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.