VDB
KO

MAL-2026-13946

Malicious code in date-fmt-helper-xz (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b384650ec0fabdd01a7dfc513cccd25156611a04c17ba0c435b950ddb9215777) date-fmt-helper-xz ships a postinstall.js that runs automatically on npm install. The script opens a TCP connection to the hardcoded remote host 8.135.48.40 on port 4444 and pipes /bin/sh stdio over the socket, granting the remote party interactive shell access on the installer's machine. Bash /dev/tcp and python3 pty.spawn fallbacks are included to maximize the chance the shell succeeds across environments. On failure of the shell paths, the script issues an HTTP GET to http://8.135.48.40/shell/failed and /shell/error with the error message, confirming the same host as attacker command-and-control. The package advertises date formatting; the reverse shell is unrelated to any legitimate functionality.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / date-fmt-helper-xz

No fixed version published yet for date-fmt-helper-xz (npm). Pin to a known-safe version or switch to an alternative.

References