MAL-2026-13698
Malicious code in simple-date-formatter-new-9 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5000b7987ca50d065efc0f5a3ba7c724cb73ac0e23f54347cff8b30aa6eb5d3b) package.json declares a postinstall script that opens an interactive bash reverse shell to the hardcoded remote address 124.221.154.135:4444 during npm install, granting the operator of that endpoint remote command execution on the installer's host. The tarball additionally ships postinstall.js, which enumerates the installer's ~/.ssh directory and POSTs the file listing along with username and platform information to https://124.221.154.135/post. Both mechanisms target the same hardcoded IP, and the reverse shell fires automatically on npm install.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for simple-date-formatter-new-9 (npm). Pin to a known-safe version or switch to an alternative.