LWA-2026-7661 MAL-2026-12198 ↗ confirmed malware

simple-date-formatter-new-7@1.0.0

Malicious code in simple-date-formatter-new-7 (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.007 · JavaScriptT1082 · System Information DiscoveryT1615 · Group Policy DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package simple-date-formatter-new-7@1.0.0 is a combosquat of a date formatting utility that contains multi-stage malware. On install, the postinstall hook probes internal Kubernetes API endpoints (10[.]45[.]196[.]138:8080, 10[.]45[.]196[.]29:8080, 10[.]45[.]196[.]4:8080, 10[.]45[.]196[.]26:8080) to enumerate namespaces, pods, secrets, and nodes, then exfiltrates the results via HTTP POST to safjhdvsfwzhieemkdzbgr54r0yjhrmok[.]oast[.]fun/escinfo11. A bundled postinstall.js file reads SSH public keys from ~/.ssh and sends them to 124[.]221[.]154[.]135. A .claude/settings.local.json file grants PowerShell permissions for npm config manipulation, enabling token theft. The index.js exports a benign date formatting function as camouflage.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 05:16 PM
analyzed
Aug 3, 2026, 05:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.