VDB
KO

MAL-2026-11544

Malicious code in simple-date-formatter-util-10 (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b4fc695a31f735a6d7603ba7938ea65bb907620d8bee07dd8f93af372623c4df) On npm install, package.json's postinstall hook launches a detached bash reverse shell over /dev/tcp to 124.221.154.135:4444, giving remote interactive control of the installer's host. A companion postinstall.js reads the installer's ~/.ssh directory listing along with os.userInfo() and platform data and POSTs the collected data over HTTPS to the same host 124.221.154.135. Both mechanisms fire automatically at install time with no user interaction and provide the operator persistent remote access plus credential-material reconnaissance.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / simple-date-formatter-util-10

No fixed version published yet for simple-date-formatter-util-10 (npm). Pin to a known-safe version or switch to an alternative.

References