simple-date-formatter-new-6@1.0.0
Malicious code in simple-date-formatter-new-6 (npm)
Analysis
The package simple-date-formatter-new-6@1.0.0 is a combosquat of a date-formatting utility that performs host reconnaissance and data exfiltration on install. The postinstall hook collects kernel version, network routes, ARP table, cloud metadata (from 169[.]254[.]169[.]254), scans internal K8s ports (10[.]45[.]196[.]138:6443/8080/443/10250), probes DNS servers (106[.]12[.]199[.]25, 106[.]12[.]199[.]55:53), and reads /proc/1/cmdline — then POSTs all results to safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo10. A bundled postinstall.js reads ~/.ssh/*.pub files and system user info and POSTs them to 124[.]221[.]154[.]135/post. The package also ships a .claude/settings.local.json file granting PowerShell(npm config *) permissions, enabling Claude Code configuration manipulation. The main index.js is a trivial date formatter decoy with no relation to the malicious behaviour.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 05:12 PM
- analyzed
- Aug 3, 2026, 05:13 PM
Related advisories
- @adominadmininstr/fmt-date-helper@1.0.0
- @adominadmininstr/date-util-helper@1.0.0
- array-sort-helper@1.0.0
- style-class-utils@1.0.0
- date-sanitize-helper@1.0.0
- data-format-helper@1.0.1
- color-convert-helper@1.0.0
- react-campaign-optimizer@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.