MAL-2026-13946

    Dashboard / Malicious Package / MAL-2026-13946

    MAL-2026-13946

    Published: 13 Aug 2026Last Modified: 13 Aug 2026

    Summary: Malicious code in date-fmt-helper-xz (npm)

    Details: Source: amazon-inspector (b384650ec0fabdd01a7dfc513cccd25156611a04c17ba0c435b950ddb9215777) date-fmt-helper-xz ships a postinstall.js that runs automatically on npm install. The script opens a TCP connection to the hardcoded remote host 8.135.48.40 on port 4444 and pipes /bin/sh stdio over the socket, granting the remote party interactive shell access on the installer's machine. Bash /dev/tcp and python3 pty.spawn fallbacks are included to maximize the chance the shell succeeds across environments. On failure of the shell paths, the script issues an HTTP GET to http://8.135.48.40/shell/failed and /shell/error with the error message, confirming the same host as attacker command-and-control. The package advertises date formatting; the reverse shell is unrelated to any legitimate functionality.

    Affected packages

    Package

    Name: date-fmt-helper-xz

    Purl: pkg:npm/date-fmt-helper-xz

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.4
    MAL-2026-13946 | CVE-DB