simple-date-formatter-new-2@1.0.0
Malicious code in simple-date-formatter-new-2 (npm)
Analysis
The package simple-date-formatter-new-2 is a combosquat of a date-formatting utility that delivers a container-escape reconnaissance implant. On npm install, the postinstall hook probes the container environment — testing tmpfs and bind mount capabilities, reading SELinux context (/proc/self/attr/current), LSM and AppArmor status, cgroup controllers, and partition tables — then exfiltrates all collected data via a curl POST to hxxp://safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo6. The oast[.]fun domain is an interactsh-style callback service used as the C2 endpoint. The package's index.js is a trivial 160-byte stub; the entire payload is in the install hook.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 04:47 PM
- analyzed
- Aug 3, 2026, 04:47 PM
Related advisories
- simple-date-formatter-new-1@1.0.0
- simple-date-formatter-util-13@1.0.0
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-12@1.0.0
- num-format-helper@1.0.0
- chart-data-utils@1.0.0
- @daylightqc/date-fmt-lite@1.1.2
- n8n-nodes-utils-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.