LWA-2026-7656 MAL-2026-12194 ↗ confirmed malware

simple-date-formatter-new-2@1.0.0

Malicious code in simple-date-formatter-new-2 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1613 · Container and Resource DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package simple-date-formatter-new-2 is a combosquat of a date-formatting utility that delivers a container-escape reconnaissance implant. On npm install, the postinstall hook probes the container environment — testing tmpfs and bind mount capabilities, reading SELinux context (/proc/self/attr/current), LSM and AppArmor status, cgroup controllers, and partition tables — then exfiltrates all collected data via a curl POST to hxxp://safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo6. The oast[.]fun domain is an interactsh-style callback service used as the C2 endpoint. The package's index.js is a trivial 160-byte stub; the entire payload is in the install hook.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 04:47 PM
analyzed
Aug 3, 2026, 04:47 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.