MAL-2026-12201
Dashboard / Malicious Package / MAL-2026-12201
MAL-2026-12201
Summary: Malicious code in simple-date-formatter-util-12 (npm)
Details: Source: amazon-inspector (cdd747d615be16a4af8508b6151d829c49f8ba2e1d045b8c1cbc9d8f2f219de9) package.json declares a postinstall script that, on npm install, collects installer reconnaissance (id, hostname, uname, cgroups, docker.sock, Linux capabilities, the Kubernetes service-account token at /var/run/secrets/kubernetes.io/serviceaccount/token, mounts, network config, ARP, PID1 cmdline, and environment variables filtered for kube/aws/token/secret/key/pass/role/region/cluster) and POSTs the collected data over plain HTTP to a Project Discovery interact.sh subdomain (http://ycrqyyjhwepdmhjifyccxss1hrks8lcd2.oast.fun/escinfo). The tarball also ships postinstall.js which enumerates the user's ~/.ssh directory and POSTs the contents plus username/platform to a hardcoded IP (https://124.221.154.135/post). The advertised functionality is a one-line formatDate wrapper around toLocaleDateString in index.js, which serves only as a cover for the malicious install-time payload.
Affected packages
Package
Name: simple-date-formatter-util-12
Purl: pkg:npm/simple-date-formatter-util-12
Affected ranges
Type: N/A
Events:
