{"id":"MAL-2026-12175","summary":"Malicious code in datefmt-pro (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (addca973f3384757b9ff2e00e5becd70e509ef5233c4cd2dc6ce73019b467787)\ndatefmt-pro presents itself as a date formatting utility, but its actual behavior is an install-time reconnaissance beacon. The scripts.postinstall entry runs postinstall.js on npm install, which uses child_process.execSync to run hostname, whoami, uname -a, and pwd, and calls os.networkInterfaces() to enumerate non-internal IPv4 addresses. It then POSTs the collected identity and internal network information as JSON over plain HTTP to the hardcoded bare-IP endpoint http://129.204.76.212:9999/rce-poc. index.js contains only a trivial date-formatting stub whose in-source comments state it exists to make the package look like a real date library while the payload lives in postinstall.js. The package name imitates a plausible utility to attract installers via typo/trust; the advertised purpose does not require any host reconnaissance or outbound network activity at install time.\n","modified":"2026-08-05T14:36:17.437973524Z","published":"2026-08-05T09:10:03Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T09:10:03Z","sha256":"dbb14f65bcc614fa6337db8dbdb57db7586f3d2897de9165b73ba3b98675e263","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-014573","import_time":"2026-08-05T09:28:26.872589487Z"},{"import_time":"2026-08-05T14:19:48.182934465Z","modified_time":"2026-08-05T13:19:18Z","sha256":"6019431ae57e04e7ec9eb38009d7feb179e15a6aa7d88c14e384ae04ae3ef7b8","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-014972"},{"id":"IN-MAL-2026-014976","import_time":"2026-08-05T14:19:48.551784531Z","modified_time":"2026-08-05T13:26:50Z","sha256":"addca973f3384757b9ff2e00e5becd70e509ef5233c4cd2dc6ce73019b467787","source":"amazon-inspector","versions":["1.0.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/datefmt-pro/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/datefmt-pro/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/datefmt-pro/v/1.0.1"}],"affected":[{"package":{"name":"datefmt-pro","ecosystem":"npm","purl":"pkg:npm/datefmt-pro"},"versions":["1.0.2","1.0.0","1.0.1"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"a896ce5c59c66d4dec329d2ee47acab75329631507f218e05f4a61cc361d457a","tlsh":"fc4166b300f993a028662895150ba5113325c0133a19fdd0bbdd03988fcab2ca773bad","path":"postinstall.js"},{"path":"package.json","sha256":"567034ef246b79b079f0f1157a727f62c335da947246527696d54725a1c608a2","tlsh":"7ee06838c9309e372dc40a5a4d56c4077f150c1708487c0433a7515c475e67b80bf30d"}],"package_integrity":[{"filename":"datefmt-pro-1.0.2.tgz","hashes":{"sha1":"6907c8ec4f1e0d6b602ab7692422a7614bdbabdd","sha512_sri":"sha512-ciHq7tILbN6YKPPNDpXy4mj7RxWAb6t21dEqkJZT0pfdoBntqUfc8zFA4R3TM9ghoXymLWbtPxUatcOe9FFx7A=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/datefmt-pro/MAL-2026-12175.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}