MAL-2026-12197

    Dashboard / Malicious Package / MAL-2026-12197

    MAL-2026-12197

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in simple-date-formatter-new-6 (npm)

    Details: Source: amazon-inspector (fcbd38bc87a61131881784bb9e919a03a4cfa2f69934fd17e3735b34ce75e3f6) package.json declares a postinstall script that runs a shell pipeline collecting host identifiers (uname, id), routing and ARP tables, TCP-probe results against internal hosts, cloud instance metadata from 169.254.169.254, and PID 1 cmdline, then POSTs the aggregated output over plain HTTP to safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo10 (an interact.sh OAST callback host). A sibling postinstall.js enumerates ~/.ssh and POSTs a JSON payload including username, platform, and.pub filenames to the hardcoded IP 124.221.154.135:443/post. Both behaviors fire as install-time side effects and provide the publisher with reconnaissance data and cloud-credential-adjacent metadata from any host that runs npm install on this package.

    Affected packages

    Package

    Name: simple-date-formatter-new-6

    Purl: pkg:npm/simple-date-formatter-new-6

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-12197 | CVE-DB