MAL-2026-11502

    Dashboard / Malicious Package / MAL-2026-11502

    MAL-2026-11502

    Published: 3 Aug 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in simple-date-formatter-new-1 (npm)

    Details: Source: amazon-inspector (628527c388185356d23a8905edf240a32c062afb06c00a58c0101ffd4bcc5182) On npm install, the package.json postinstall hook executes a shell one-liner that attempts to mount the host block device via mknod, enumerates /etc/kubernetes and kubelet pod directories, reads the Kubernetes service-account token at /var/run/secrets/kubernetes.io/serviceaccount/token, lists home directory contents, and POSTs the collected output to http://safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo4 (an interact.sh OAST callback subdomain). A sibling postinstall.js in the tarball reads the installer's ~/.ssh directory via getSSHKeys() and POSTs a JSON payload containing SSH contents, username, and platform to hardcoded IP 124.221.154.135 on port 443. The package advertises itself as a date formatter but ships no such functionality; its only effect on install is host reconnaissance and credential exfiltration. Source: ossf-package-analysis (037638085662ef2cec04655349a528b60480aa642606d96eba158e62161b3a51) The OpenSSF Package Analysis project identified 'simple-date-formatter-new-1' @ 1.0.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.

    Affected packages

    Package

    Name: simple-date-formatter-new-1

    Purl: pkg:npm/simple-date-formatter-new-1

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-11502 | CVE-DB