MAL-2026-11106

    Dashboard / Malicious Package / MAL-2026-11106

    MAL-2026-11106

    Published: 28 Jul 2026Last Modified: 28 Jul 2026

    Summary: Malicious code in date-sanitize-helper (npm)

    Details: Source: amazon-inspector (33b6764b7711cfa03cf6b3a2f70e24b3256a61ac9319d45200ada236fe7c3ed2) The package is advertised as a date parsing/sanitization helper but its postinstall.js runs automatically on npm install and performs installer-side data collection unrelated to the stated purpose. The script shells out via child_process/exec and curl to gather hostname, current user, id output, sudo -l output, uname, cwd, container indicators, GitHub Actions environment, running process list, and network information. It filters environment variables against a credential keyword set (KEY, TOKEN, SECRET, CREDENTIAL, KUBE, JENKINS, NPM, GEM, CARGO, AZURE, GCP, AWS_, GH_TOKEN, GITHUB_TOKEN) and probes cloud instance-metadata endpoints (AWS 169.254.169.254, Tencent, Aliyun). The aggregated output is base64-encoded and posted via curl to the hardcoded host pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com (a Burp Collaborator subdomain). Postinstall.js contains Chinese-language comments describing a 'compact exfil version', and index.js is an unrelated small color utility, indicating deliberate cover-story metadata. Source: ossf-package-analysis (0ad5bc011fffec78eedbae93d69fa652c21868e6a8492f3c4a34cdb08dffd6e1) The OpenSSF Package Analysis project identified 'date-sanitize-helper' @ 1.0.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.

    Affected packages

    Package

    Name: date-sanitize-helper

    Purl: pkg:npm/date-sanitize-helper

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0