MAL-2026-17229
Malicious code in simple-date-formatter-new-12 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (bd79db99adb8878673dd85db5a29661432808fa8fcc5e3d750b907418df8ae5f) npm package simple-date-formatter-new-12@1.0.0 declares a postinstall lifecycle script in package.json that runs automatically on `npm install`. The script uses curl to fetch an internal Baidu host (http://bsrc-ssrf.n.baidu-int.com/...), writes the response to /tmp/bsrc.txt, and POSTs the contents to an attacker-controlled interactsh collector at pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun/bsrc. The package's advertised purpose is a trivial date-formatting wrapper (index.js exports a single formatDate function); the SSRF probe and outbound exfiltration are unrelated to that purpose. The name shape (`simple-date-formatter-new-12`), empty author metadata, and OAST beacon are consistent with a dependency-confusion / typosquat probe designed to detect installation inside a target organization and leak internal network responses reachable from the installer's network position to a third-party collector.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for simple-date-formatter-new-12 (npm). Pin to a known-safe version or switch to an alternative.