VDB
KO

MAL-2026-11546

Malicious code in simple-date-formatter-util-6 (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (e3c4633742f36d29ca968a2ce71c97cb81e9cb2d2c76738742bb39de671cb115) Package advertises a trivial formatDate utility but ships a malicious npm postinstall hook. The postinstall script launches a backgrounded interactive bash reverse shell via /dev/tcp/124.221.154.135/4444, granting a remote party shell access on the installer's host at install time. A companion postinstall.js reads the installer's ~/.ssh directory listing along with OS username/platform information and POSTs it over HTTPS to the same hardcoded IP (124.221.154.135:443, path /post). The advertised formatDate export in index.js is a decoy; the package name pattern and empty author metadata are consistent with a typosquat/decoy lure whose sole functional effect is install-time compromise of the installer machine.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / simple-date-formatter-util-6

No fixed version published yet for simple-date-formatter-util-6 (npm). Pin to a known-safe version or switch to an alternative.

References