-= Per source details. Do not edit below this line.=-
package.json declares a postinstall shell pipeline that attempts to mknod and mount the host block device at /tmp/hostroot, enumerates /etc/kubernetes and kubelet pods, reads the Kubernetes service-account token at /var/run/secrets/kubernetes.io/serviceaccount/token, lists /home/work/skills/canvas-agent/, dumps /proc/net/arp, and POSTs the collected output via curl to http://safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo4 (an interactsh OAST subdomain). A companion postinstall.js in the tarball enumerates the installer's ~/.ssh directory, collects filenames alongside os.userInfo(), and POSTs the result over HTTPS to the hardcoded IP 124.221.154.135:443/post. The package's declared purpose ("simple date formatter") has no relationship to reading Kubernetes secrets, host block devices, or SSH keys. Install-time execution of this script harvests container-escape and credential material and ships it to attacker-controlled destinations.
{
"malicious-packages-origins": [
{
"source": "amazon-inspector",
"modified_time": "2026-08-04T22:05:09Z",
"sha256": "4f79e44f447b3ebd6b246845f4c31bff0a0fe2e3bc45b220e1a952bf1ddc66bb",
"id": "IN-MAL-2026-011324",
"versions": [
"1.0.0"
],
"import_time": "2026-08-04T22:30:10.967742604Z"
}
]
}[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-A40o796xbvVOPBuCMN9gb3cvNwVaO+E9K0t9wkMzhS71cR7Ixz2atL25LSJPtIwdNQNdkIz2b0l98e5C7fc1pw==",
"sha1": "8408000c7c834686a95ec6efc50b120eec41841d"
},
"filename": "simple-date-formatter-util-15-1.0.0.tgz"
}
],
"evidence_files": [
{
"path": "package.json",
"sha256": "9c1d7f77e9abed4c051b2b1b1e35f8178918317bb04e56a28c9a8077a3f01383",
"tlsh": "2b11ce41f5508e735ecdc9a52c170348b9c2a80f1a1a3d0ce5c7a638a19c6f2c479f47"
},
{
"path": "postinstall.js",
"sha256": "f2be6940c08d36a7f1ce83d5fe16fefd8c14edda5d124e0f6406725beb5020ef",
"tlsh": "273165d558f9cd3007778685639b91263102fe13650ee940f3c807a51fe9a5449f2dee"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/simple-date-formatter-util-15/MAL-2026-11545.json"