-= Per source details. Do not edit below this line.=-
The package's npm postinstall script curls cloud instance-metadata endpoints (AWS 169.254.169.254, Alibaba 100.100.100.200, Tencent metadata.tencentyun.com and 169.254.0.23), retrieves the AWS IAM security-credentials for the attached instance role, lists /data/, and POSTs the collected output to a hardcoded attacker-controlled interact.sh (OAST) subdomain at ycrqyyjhwepdmhjifyccxss1hrks8lcd2.oast.fun. A bundled postinstall.js additionally reads the installer's ~/.ssh directory and POSTs username, platform, and key-file listings via HTTPS to the hardcoded IP 124.221.154.135:443/post. The declared package purpose (date formatting utility) has no relationship to cloud metadata queries or SSH-directory enumeration. Running npm install on this package hands short-lived IAM credentials and SSH material to the attacker.
{
"malicious-packages-origins": [
{
"modified_time": "2026-08-05T08:49:26Z",
"source": "amazon-inspector",
"sha256": "44b1bd8b606c30f6ac8c150379645ef93991c3864d4063891d5b2f96c1a4ff5d",
"import_time": "2026-08-05T09:28:10.239665263Z",
"id": "IN-MAL-2026-014431",
"versions": [
"1.0.1"
]
},
{
"modified_time": "2026-08-05T08:49:41Z",
"source": "amazon-inspector",
"sha256": "f6ec6c790f702e0bb6617bb6bf16ad8b3a154bc7d539938535cde7a2cf205f17",
"import_time": "2026-08-05T09:28:10.551322575Z",
"id": "IN-MAL-2026-014433",
"versions": [
"1.0.0"
]
}
]
}{
"package_integrity": [
{
"filename": "simple-date-formatter-util-4-1.0.1.tgz",
"hashes": {
"sha512_sri": "sha512-/XnFCAFBJ+6lu8Nx3QOGMolQW/VVa3y1VJTz3ZsadJn45106xYnMWGhHssZ1Smf2t59qy30nnZ+Zze3flxbO5Q==",
"sha1": "48924b4a9f688e2415d07e2279d46a4782408cf9"
}
}
],
"evidence_files": [
{
"tlsh": "ea11608c6961b9731fca9f69d269474eb920fd471bc01e04d2961cf45d4e7a2707970c",
"sha256": "d9cb5675c98c8ee1cda0711bd200b22a7b697b118a7b8a153e5b7d8a0097ba9b",
"path": "package.json"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/simple-date-formatter-util-4/MAL-2026-12205.json"
[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]