LWA-2026-7660 MAL-2026-12197 ↗ confirmed malware

simple-date-formatter-new-6@1.0.0

Malicious code in simple-date-formatter-new-6 (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.007 · JavaScriptT1082 · System Information DiscoveryT1615 · Group Policy DiscoveryT1046 · Network Service DiscoveryT1552.004 · Private KeysT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package simple-date-formatter-new-6@1.0.0 is a combosquat of a date-formatting utility that performs host reconnaissance and data exfiltration on install. The postinstall hook collects kernel version, network routes, ARP table, cloud metadata (from 169[.]254[.]169[.]254), scans internal K8s ports (10[.]45[.]196[.]138:6443/8080/443/10250), probes DNS servers (106[.]12[.]199[.]25, 106[.]12[.]199[.]55:53), and reads /proc/1/cmdline — then POSTs all results to safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo10. A bundled postinstall.js reads ~/.ssh/*.pub files and system user info and POSTs them to 124[.]221[.]154[.]135/post. The package also ships a .claude/settings.local.json file granting PowerShell(npm config *) permissions, enabling Claude Code configuration manipulation. The main index.js is a trivial date formatter decoy with no relation to the malicious behaviour.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 05:12 PM
analyzed
Aug 3, 2026, 05:13 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.