LWA-2026-7657 MAL-2026-12195 ↗ confirmed malware

simple-date-formatter-new-3@1.0.0

Malicious code in simple-date-formatter-new-3 (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.007 · JavaScriptT1082 · System Information DiscoveryT1610 · Deploy ContainerT1552.004 · Private KeysT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

simple-date-formatter-new-3 is a combosquat of a date-formatting utility. On install, the postinstall hook runs a shell script that performs container-escape reconnaissance (enumerating kernel version, cgroups, process namespaces, block devices, and attempting cgroup escape via mknod+mount) and pipes the results to safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo7. A bundled postinstall.js reads SSH public keys from ~/.ssh/ and exfiltrates them via HTTPS POST to 124[.]221[.]154[.]135. The package also ships a .claude/settings.local.json that grants PowerShell(npm config *) permissions, suggesting npm token theft as a secondary objective.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 04:55 PM
analyzed
Aug 3, 2026, 04:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.