simple-date-formatter-new-1@1.0.0
Malicious code in simple-date-formatter-new-1 (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.007 · JavaScriptT1082 · System Information DiscoveryT1613 · Container and Resource DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
simple-date-formatter-new-1@1.0.0 is a combosquat package impersonating date-formatting utilities. Its postinstall script performs container escape (creates a block device node and mounts the host root filesystem), then exfiltrates Kubernetes service-account tokens, pod listings, cluster configuration, CI agent directory contents, and the ARP table via a curl POST to safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo4. A bundled postinstall.js additionally steals SSH private keys and exfiltrates them to 124[.]221[.]154[.]135:443.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 04:25 PM
- analyzed
- Aug 3, 2026, 04:26 PM
Related advisories
- simple-date-formatter-util-13@1.0.0
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-12@1.0.0
- num-format-helper@1.0.0
- chart-data-utils@1.0.0
- @daylightqc/date-fmt-lite@1.1.2
- n8n-nodes-utils-helper@1.0.0
- antsrcsrctest@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.