MAL-2026-11544

    Dashboard / Malicious Package / MAL-2026-11544

    MAL-2026-11544

    Published: 4 Aug 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in simple-date-formatter-util-10 (npm)

    Details: Source: amazon-inspector (b4fc695a31f735a6d7603ba7938ea65bb907620d8bee07dd8f93af372623c4df) On npm install, package.json's postinstall hook launches a detached bash reverse shell over /dev/tcp to 124.221.154.135:4444, giving remote interactive control of the installer's host. A companion postinstall.js reads the installer's ~/.ssh directory listing along with os.userInfo() and platform data and POSTs the collected data over HTTPS to the same host 124.221.154.135. Both mechanisms fire automatically at install time with no user interaction and provide the operator persistent remote access plus credential-material reconnaissance.

    Affected packages

    Package

    Name: simple-date-formatter-util-10

    Purl: pkg:npm/simple-date-formatter-util-10

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-11544 | CVE-DB