MAL-2026-12203

    Dashboard / Malicious Package / MAL-2026-12203

    MAL-2026-12203

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in simple-date-formatter-util-14 (npm)

    Details: Source: amazon-inspector (043fc72acaebb0b8e96a80ee338611c81567284213ea047911a851d3f00dcc46) package.json declares a postinstall lifecycle script that runs a shell pipeline enumerating /home/work directory contents, probing the internal Kubernetes API server, and reading /proc namespace/mount/capability info, then POSTs the collected output to http://safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo3 (an interact.sh OAST collector). The tarball also ships postinstall.js, which enumerates the installer's ~/.ssh directory via os.homedir() and POSTs the file listing plus user/platform info to a hardcoded bare-IP endpoint https://124.221.154.135/post. Neither behavior is related to the package's stated date-formatting purpose, and both fire on npm install.

    Affected packages

    Package

    Name: simple-date-formatter-util-14

    Purl: pkg:npm/simple-date-formatter-util-14

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-12203 | CVE-DB