{"id":"MAL-2026-12205","summary":"Malicious code in simple-date-formatter-util-4 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f6ec6c790f702e0bb6617bb6bf16ad8b3a154bc7d539938535cde7a2cf205f17)\nThe package's npm postinstall script curls cloud instance-metadata endpoints (AWS 169.254.169.254, Alibaba 100.100.100.200, Tencent metadata.tencentyun.com and 169.254.0.23), retrieves the AWS IAM security-credentials for the attached instance role, lists /data/, and POSTs the collected output to a hardcoded attacker-controlled interact.sh (OAST) subdomain at ycrqyyjhwepdmhjifyccxss1hrks8lcd2.oast.fun. A bundled postinstall.js additionally reads the installer's ~/.ssh directory and POSTs username, platform, and key-file listings via HTTPS to the hardcoded IP 124.221.154.135:443/post. The declared package purpose (date formatting utility) has no relationship to cloud metadata queries or SSH-directory enumeration. Running `npm install` on this package hands short-lived IAM credentials and SSH material to the attacker.\n","modified":"2026-08-05T10:06:22.782810738Z","published":"2026-08-05T08:49:26Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T08:49:26Z","sha256":"44b1bd8b606c30f6ac8c150379645ef93991c3864d4063891d5b2f96c1a4ff5d","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-014431","import_time":"2026-08-05T09:28:10.239665263Z"},{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-014433","import_time":"2026-08-05T09:28:10.551322575Z","modified_time":"2026-08-05T08:49:41Z","sha256":"f6ec6c790f702e0bb6617bb6bf16ad8b3a154bc7d539938535cde7a2cf205f17"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/simple-date-formatter-util-4/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/simple-date-formatter-util-4/v/1.0.0"}],"affected":[{"package":{"name":"simple-date-formatter-util-4","ecosystem":"npm","purl":"pkg:npm/simple-date-formatter-util-4"},"versions":["1.0.1","1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"simple-date-formatter-util-4-1.0.1.tgz","hashes":{"sha1":"48924b4a9f688e2415d07e2279d46a4782408cf9","sha512_sri":"sha512-/XnFCAFBJ+6lu8Nx3QOGMolQW/VVa3y1VJTz3ZsadJn45106xYnMWGhHssZ1Smf2t59qy30nnZ+Zze3flxbO5Q=="}}],"evidence_files":[{"path":"package.json","sha256":"d9cb5675c98c8ee1cda0711bd200b22a7b697b118a7b8a153e5b7d8a0097ba9b","tlsh":"ea11608c6961b9731fca9f69d269474eb920fd471bc01e04d2961cf45d4e7a2707970c"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/simple-date-formatter-util-4/MAL-2026-12205.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}