VDB
EN

MAL-2026-11545

Malicious code in simple-date-formatter-util-15 (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (4f79e44f447b3ebd6b246845f4c31bff0a0fe2e3bc45b220e1a952bf1ddc66bb) package.json declares a postinstall shell pipeline that attempts to mknod and mount the host block device at /tmp/hostroot, enumerates /etc/kubernetes and kubelet pods, reads the Kubernetes service-account token at /var/run/secrets/kubernetes.io/serviceaccount/token, lists /home/work/skills/canvas-agent/, dumps /proc/net/arp, and POSTs the collected output via curl to http://safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo4 (an interactsh OAST subdomain). A companion postinstall.js in the tarball enumerates the installer's ~/.ssh directory, collects filenames alongside os.userInfo(), and POSTs the result over HTTPS to the hardcoded IP 124.221.154.135:443/post. The package's declared purpose ("simple date formatter") has no relationship to reading Kubernetes secrets, host block devices, or SSH keys. Install-time execution of this script harvests container-escape and credential material and ships it to attacker-controlled destinations.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / simple-date-formatter-util-15

No fixed version published yet for simple-date-formatter-util-15 (npm). Pin to a known-safe version or switch to an alternative.

참고