MAL-2026-12194
Dashboard / Malicious Package / MAL-2026-12194
MAL-2026-12194
Summary: Malicious code in simple-date-formatter-new-2 (npm)
Details: Source: amazon-inspector (1a752053edcc35b1de91b1eb5bb0a8b18e22ac32120f4b8871ecf84c3c4aec54) The package presents itself as a trivial date-formatting utility (index.js exports a one-line wrapper around toLocaleDateString), but its package.json postinstall script runs a shell pipeline that probes sandbox and host state (tmpfs mount capability, bind-mount of /home/work, /proc/self/attr/current, LSM/AppArmor info, cgroups layout, /proc/partitions, and a listing of /home/work) and POSTs the combined output via curl to http://safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo6, an interactsh/OAST out-of-band callback domain. The tarball additionally ships postinstall.js, which reads the installer's ~/.ssh directory, packages the filenames together with the local username and platform, and POSTs the JSON over HTTPS to the hardcoded IP 124.221.154.135:443/post; Chinese-language comments in that file describe stealing SSH keys and sending them to a C2. The benign facade contradicts the install-time behavior and the shipped stealer module.
Affected packages
Package
Name: simple-date-formatter-new-2
Purl: pkg:npm/simple-date-formatter-new-2
Affected ranges
Type: N/A
Events:
