MAL-2026-11546
Dashboard / Malicious Package / MAL-2026-11546
MAL-2026-11546
Summary: Malicious code in simple-date-formatter-util-6 (npm)
Details: Source: amazon-inspector (e3c4633742f36d29ca968a2ce71c97cb81e9cb2d2c76738742bb39de671cb115) Package advertises a trivial formatDate utility but ships a malicious npm postinstall hook. The postinstall script launches a backgrounded interactive bash reverse shell via /dev/tcp/124.221.154.135/4444, granting a remote party shell access on the installer's host at install time. A companion postinstall.js reads the installer's ~/.ssh directory listing along with OS username/platform information and POSTs it over HTTPS to the same hardcoded IP (124.221.154.135:443, path /post). The advertised formatDate export in index.js is a decoy; the package name pattern and empty author metadata are consistent with a typosquat/decoy lure whose sole functional effect is install-time compromise of the installer machine.
Affected packages
Package
Name: simple-date-formatter-util-6
Purl: pkg:npm/simple-date-formatter-util-6
Affected ranges
Type: N/A
Events:
