MAL-2026-11545

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/simple-date-formatter-util-15/MAL-2026-11545.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11545
Published
2026-08-04T22:05:09Z
Modified
2026-08-04T23:05:30.449797525Z
Summary
Malicious code in simple-date-formatter-util-15 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (4f79e44f447b3ebd6b246845f4c31bff0a0fe2e3bc45b220e1a952bf1ddc66bb)

package.json declares a postinstall shell pipeline that attempts to mknod and mount the host block device at /tmp/hostroot, enumerates /etc/kubernetes and kubelet pods, reads the Kubernetes service-account token at /var/run/secrets/kubernetes.io/serviceaccount/token, lists /home/work/skills/canvas-agent/, dumps /proc/net/arp, and POSTs the collected output via curl to http://safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo4 (an interactsh OAST subdomain). A companion postinstall.js in the tarball enumerates the installer's ~/.ssh directory, collects filenames alongside os.userInfo(), and POSTs the result over HTTPS to the hardcoded IP 124.221.154.135:443/post. The package's declared purpose ("simple date formatter") has no relationship to reading Kubernetes secrets, host block devices, or SSH keys. Install-time execution of this script harvests container-escape and credential material and ships it to attacker-controlled destinations.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-04T22:05:09Z",
            "sha256": "4f79e44f447b3ebd6b246845f4c31bff0a0fe2e3bc45b220e1a952bf1ddc66bb",
            "id": "IN-MAL-2026-011324",
            "versions": [
                "1.0.0"
            ],
            "import_time": "2026-08-04T22:30:10.967742604Z"
        }
    ]
}
References
Credits

Affected packages

npm / simple-date-formatter-util-15

Package

Name
simple-date-formatter-util-15
View open source insights on deps.dev
Purl
pkg:npm/simple-date-formatter-util-15

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-A40o796xbvVOPBuCMN9gb3cvNwVaO+E9K0t9wkMzhS71cR7Ixz2atL25LSJPtIwdNQNdkIz2b0l98e5C7fc1pw==",
                "sha1": "8408000c7c834686a95ec6efc50b120eec41841d"
            },
            "filename": "simple-date-formatter-util-15-1.0.0.tgz"
        }
    ],
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "9c1d7f77e9abed4c051b2b1b1e35f8178918317bb04e56a28c9a8077a3f01383",
            "tlsh": "2b11ce41f5508e735ecdc9a52c170348b9c2a80f1a1a3d0ce5c7a638a19c6f2c479f47"
        },
        {
            "path": "postinstall.js",
            "sha256": "f2be6940c08d36a7f1ce83d5fe16fefd8c14edda5d124e0f6406725beb5020ef",
            "tlsh": "273165d558f9cd3007778685639b91263102fe13650ee940f3c807a51fe9a5449f2dee"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/simple-date-formatter-util-15/MAL-2026-11545.json"