MAL-2026-11099

    Dashboard / Malicious Package / MAL-2026-11099

    MAL-2026-11099

    Published: 27 Jul 2026Last Modified: 5 Aug 2026Aliases: 
    GHSA-xcf3-mw56-cqm5

    Summary: Malicious code in demo-awesome-date-parser-test (npm)

    Details: Source: amazon-inspector (e5cccf4c1379e6c3f9af7dde45277b1c4db552a0ad878bc08378ad6e8879b497) The package advertises itself as a date parser but ships a heavily obfuscated payload in src/index.js. The exported demoParseDate function invokes injectScriptIfNeeded, which registers a jQuery form-submission handler that reads submitted form field values, stores them in localStorage under keys 'sendToUnload_secretData' and 'sendToUnload_secretDataBase64', and POSTs them via fetch to a URL built from location.host with the path '/leak?data_stolen_on_unload_base64='. A window unload handler additionally exfiltrates the buffered values twice via navigator.sendBeacon to the same '/leak?...' path. injectScriptIfNeeded also loads remote JavaScript by evaluating a dynamic import of '<host>/tag_added_via_script_import.js' and by appending a <script src='//<host>/tag_added_via_script_file_tag_appending.js'> tag to the document, giving the author arbitrary in-page code execution. The module also assembles code at runtime via eval, new Function, and setInterval(setTimeout,...) on strings drawn from an obfuscated string array, and manipulates the end-user clipboard through navigator.clipboard.writeText/readText and a hidden-textarea document.execCommand('copy') that writes a literal 'malware test text copy' string. Author-written literals in the bundle ('Attack vector: eval execution', 'stolen-data-sended-on-unload-event-base64', 'Code executed on event state via window.onload') confirm intent. The package name 'demo-awesome-date-parser-test' and version 0.0.7 are consistent with a demonstration/test artifact, but the code performs real exfiltration and remote-script-loading behavior against any consumer that loads it. Source: ghsa-malware (6e554422e7b097902e753eb63c772c66845f3f19bf0c2974f6fbeb9fe441ec34) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

    Affected packages

    Package

    Name: demo-awesome-date-parser-test

    Purl: pkg:npm/demo-awesome-date-parser-test

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.7
    0.0.6
    0.0.5
    0.0.4
    0.0.3
    0.0.2
    0.0.1
    MAL-2026-11099 | CVE-DB