MAL-2026-12204
Dashboard / Malicious Package / MAL-2026-12204
MAL-2026-12204
Summary: Malicious code in simple-date-formatter-util-16 (npm)
Details: Source: amazon-inspector (3d57172cd3c0a47afc03e1a15ca2ead758bb6f5c78a2234d42487d65cb4944c5) package.json declares a postinstall script that runs automatically on `npm install`. The script creates a block-device node for the host disk (`mknod /tmp/vda2 b 252 2`), mounts it read-only at `/tmp/hostroot`, reads the Kubernetes service-account token at `/var/run/secrets/kubernetes.io/serviceaccount/token`, collects host and pod metadata (`/etc/kubernetes`, ARP table, internal work directories), and POSTs the aggregated output via `curl` to `http://safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo4`. The behavior combines container-escape reconnaissance against a Kubernetes node with credential and host-data exfiltration to an out-of-band interaction domain.
Affected packages
Package
Name: simple-date-formatter-util-16
Purl: pkg:npm/simple-date-formatter-util-16
Affected ranges
Type: N/A
Events:
