simple-date-formatter-new-7@1.0.0
Malicious code in simple-date-formatter-new-7 (npm)
Analysis
The package simple-date-formatter-new-7@1.0.0 is a combosquat of a date formatting utility that contains multi-stage malware. On install, the postinstall hook probes internal Kubernetes API endpoints (10[.]45[.]196[.]138:8080, 10[.]45[.]196[.]29:8080, 10[.]45[.]196[.]4:8080, 10[.]45[.]196[.]26:8080) to enumerate namespaces, pods, secrets, and nodes, then exfiltrates the results via HTTP POST to safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo11. A bundled postinstall.js file reads SSH public keys from ~/.ssh and sends them to 124[.]221[.]154[.]135. A .claude/settings.local.json file grants PowerShell permissions for npm config manipulation, enabling token theft. The index.js exports a benign date formatting function as camouflage.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 05:16 PM
- analyzed
- Aug 3, 2026, 05:17 PM
Related advisories
- simple-date-formatter-new-6@1.0.0
- @adominadmininstr/fmt-date-helper@1.0.0
- @adominadmininstr/date-util-helper@1.0.0
- array-sort-helper@1.0.0
- style-class-utils@1.0.0
- date-sanitize-helper@1.0.0
- data-format-helper@1.0.1
- color-convert-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.