MAL-2026-11546

    Dashboard / Malicious Package / MAL-2026-11546

    MAL-2026-11546

    Published: 4 Aug 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in simple-date-formatter-util-6 (npm)

    Details: Source: amazon-inspector (e3c4633742f36d29ca968a2ce71c97cb81e9cb2d2c76738742bb39de671cb115) Package advertises a trivial formatDate utility but ships a malicious npm postinstall hook. The postinstall script launches a backgrounded interactive bash reverse shell via /dev/tcp/124.221.154.135/4444, granting a remote party shell access on the installer's host at install time. A companion postinstall.js reads the installer's ~/.ssh directory listing along with OS username/platform information and POSTs it over HTTPS to the same hardcoded IP (124.221.154.135:443, path /post). The advertised formatDate export in index.js is a decoy; the package name pattern and empty author metadata are consistent with a typosquat/decoy lure whose sole functional effect is install-time compromise of the installer machine.

    Affected packages

    Package

    Name: simple-date-formatter-util-6

    Purl: pkg:npm/simple-date-formatter-util-6

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-11546 | CVE-DB