MAL-2026-11502
Dashboard / Malicious Package / MAL-2026-11502
MAL-2026-11502
Summary: Malicious code in simple-date-formatter-new-1 (npm)
Details: Source: amazon-inspector (628527c388185356d23a8905edf240a32c062afb06c00a58c0101ffd4bcc5182) On npm install, the package.json postinstall hook executes a shell one-liner that attempts to mount the host block device via mknod, enumerates /etc/kubernetes and kubelet pod directories, reads the Kubernetes service-account token at /var/run/secrets/kubernetes.io/serviceaccount/token, lists home directory contents, and POSTs the collected output to http://safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo4 (an interact.sh OAST callback subdomain). A sibling postinstall.js in the tarball reads the installer's ~/.ssh directory via getSSHKeys() and POSTs a JSON payload containing SSH contents, username, and platform to hardcoded IP 124.221.154.135 on port 443. The package advertises itself as a date formatter but ships no such functionality; its only effect on install is host reconnaissance and credential exfiltration. Source: ossf-package-analysis (037638085662ef2cec04655349a528b60480aa642606d96eba158e62161b3a51) The OpenSSF Package Analysis project identified 'simple-date-formatter-new-1' @ 1.0.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.
Affected packages
Package
Name: simple-date-formatter-new-1
Purl: pkg:npm/simple-date-formatter-new-1
Affected ranges
Type: N/A
Events:
