MAL-2026-12197
Dashboard / Malicious Package / MAL-2026-12197
MAL-2026-12197
Summary: Malicious code in simple-date-formatter-new-6 (npm)
Details: Source: amazon-inspector (fcbd38bc87a61131881784bb9e919a03a4cfa2f69934fd17e3735b34ce75e3f6) package.json declares a postinstall script that runs a shell pipeline collecting host identifiers (uname, id), routing and ARP tables, TCP-probe results against internal hosts, cloud instance metadata from 169.254.169.254, and PID 1 cmdline, then POSTs the aggregated output over plain HTTP to safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo10 (an interact.sh OAST callback host). A sibling postinstall.js enumerates ~/.ssh and POSTs a JSON payload including username, platform, and.pub filenames to the hardcoded IP 124.221.154.135:443/post. Both behaviors fire as install-time side effects and provide the publisher with reconnaissance data and cloud-credential-adjacent metadata from any host that runs npm install on this package.
Affected packages
Package
Name: simple-date-formatter-new-6
Purl: pkg:npm/simple-date-formatter-new-6
Affected ranges
Type: N/A
Events:
