MAL-2026-11544
Dashboard / Malicious Package / MAL-2026-11544
MAL-2026-11544
Summary: Malicious code in simple-date-formatter-util-10 (npm)
Details: Source: amazon-inspector (b4fc695a31f735a6d7603ba7938ea65bb907620d8bee07dd8f93af372623c4df) On npm install, package.json's postinstall hook launches a detached bash reverse shell over /dev/tcp to 124.221.154.135:4444, giving remote interactive control of the installer's host. A companion postinstall.js reads the installer's ~/.ssh directory listing along with os.userInfo() and platform data and POSTs the collected data over HTTPS to the same host 124.221.154.135. Both mechanisms fire automatically at install time with no user interaction and provide the operator persistent remote access plus credential-material reconnaissance.
Affected packages
Package
Name: simple-date-formatter-util-10
Purl: pkg:npm/simple-date-formatter-util-10
Affected ranges
Type: N/A
Events:
