MAL-2026-11998

    Dashboard / Malicious Package / MAL-2026-11998

    MAL-2026-11998

    Published: 4 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in simple-date-formatter-util-7 (npm)

    Details: Source: amazon-inspector (e53aca949f6ef9820b220363a2b0c7df91e36f08ded73165dfe9140a004fd693) Package advertises itself as a date formatter utility but ships a malicious postinstall payload. package.json declares a postinstall lifecycle script that spawns an interactive bash reverse shell over /dev/tcp to 124.221.154.135:4444, giving a remote party command execution on the installer's host immediately after `npm install`. A bundled postinstall.js additionally enumerates the installer's ~/.ssh directory and POSTs the listing along with username and platform metadata to the same host at 124.221.154.135 over HTTPS. Advertised purpose (date formatting) does not require network access, shell execution, or SSH directory reads.

    Affected packages

    Package

    Name: simple-date-formatter-util-7

    Purl: pkg:npm/simple-date-formatter-util-7

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-11998 | CVE-DB