LWA-2026-7659 MAL-2026-11543 ↗ confirmed malware

simple-date-formatter-new-5@1.0.0

Malicious code in simple-date-formatter-new-5 (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1046 · Network Service DiscoveryT1613 · Container and Resource DiscoveryT1525 · Implant Internal ImageT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The postinstall hook runs a shell script that fingerprints the host (kernel version, network interfaces), probes Kubernetes API servers on internal IPs (10[.]45[.]196[.]138:6443, 10250, 8080), fetches cloud instance metadata from AWS (169[.]254[.]169[.]254) and Alibaba (100[.]100[.]100[.]200) endpoints, scans 6 internal hosts across ports 22/80/443/6443/2379/10250, reads ARP tables, DNS configuration, and Kubernetes service account tokens (/var/run/secrets/kubernetes[.]io/serviceaccount/). All collected data is exfiltrated via HTTP POST to safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo9. The package also ships a .claude/settings.local.json granting PowerShell permissions, targeting Claude Code AI coding agent environments. The actual index.js is a trivial 3-line date formatter — the package is a trojanized clone of a date-formatting utility.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 05:07 PM
analyzed
Aug 3, 2026, 05:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.