-= Per source details. Do not edit below this line.=-
date-fns-lite@1.0.10 presents as a lightweight date-formatting utility but ships a malicious postinstall.js that runs automatically on npm install. The script harvests installer-side secrets — AWS credentials (~/.aws), GCP application-default credentials, Azure tokens, kubeconfig, SSH private keys and authorized_keys, /etc/shadow, and shell history — using /proc/1/root traversal to reach the host filesystem from inside a container. It also queries the AWS IMDS endpoint (http://169.254.169.254/latest/meta-data/iam/security-credentials/) and GCP metadata service for instance IAM credentials, probes the Docker socket via /proc/1/root/var/run/docker.sock to enumerate containers, and performs internal-network reconnaissance (default-gateway detection, /24 ping sweep, port probes on 22/80/443/3306/6379/9200/27017). The aggregated report is POSTed to a hardcoded bare-IP endpoint at http://115.190.124.243:9082/callback over plain HTTP. The package name mimics the widely-used date-fns library, and index.js contains a small plausible-looking date formatter as cover for the postinstall payload. Installing this package on any host — especially in CI or a container with host mounts — will disclose cloud credentials, SSH keys, and an internal-network map to the attacker.
The OpenSSF Package Analysis project identified 'date-fns-lite' @ 1.0.11 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2026-07-01T22:03:01.364950268Z",
"id": "IN-MAL-2026-007947",
"sha256": "0eea3459d7924894dd7a609efe669b9e762bb88e4f939414d6f53fe16788e29f",
"modified_time": "2026-07-01T21:20:34Z",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
},
{
"import_time": "2026-07-01T22:03:01.123641375Z",
"id": "IN-MAL-2026-007942",
"sha256": "9853105f0307399f6f3f5e7eb836394fd4e73d319237033ab69966466a27342f",
"modified_time": "2026-07-01T21:19:53Z",
"source": "amazon-inspector",
"versions": [
"1.0.9"
]
},
{
"id": "IN-MAL-2026-007940",
"import_time": "2026-07-01T22:03:01.017391333Z",
"sha256": "9af195b8341421ebe7b8f512aad362785fac8589348e8bdd8f88f7722abb40c5",
"modified_time": "2026-07-01T21:19:37Z",
"source": "amazon-inspector",
"versions": [
"1.0.11"
]
},
{
"import_time": "2026-07-01T22:03:01.745944098Z",
"id": "IN-MAL-2026-007953",
"sha256": "ce45aef4b931fbf32e28f1b8faba0ddcb50ec7d31fd4bed58247df5803d1bf6d",
"modified_time": "2026-07-01T21:21:21Z",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"import_time": "2026-07-01T22:03:01.706103651Z",
"id": "IN-MAL-2026-007952",
"sha256": "0f9edf3018d73debfdf5bd44b17c05736bfcf41c6c5af81cbd50f505a9844ca6",
"versions": [
"1.0.1"
],
"source": "amazon-inspector",
"modified_time": "2026-07-01T21:21:14Z"
},
{
"import_time": "2026-07-01T22:03:01.328937289Z",
"id": "IN-MAL-2026-007946",
"sha256": "2e46efde053535d5d1b8c10671e3ada0985ee5cf1d3774925f4d78f5f955bfbd",
"modified_time": "2026-07-01T21:20:25Z",
"source": "amazon-inspector",
"versions": [
"1.0.6"
]
},
{
"id": "IN-MAL-2026-007944",
"import_time": "2026-07-01T22:03:01.235428566Z",
"sha256": "4694a079d83e33dcee7f87140c41737009d9f0b19f351c23f2ae3dbce9a47a51",
"modified_time": "2026-07-01T21:20:09Z",
"source": "amazon-inspector",
"versions": [
"1.0.10"
]
},
{
"import_time": "2026-07-01T22:03:01.297111308Z",
"id": "IN-MAL-2026-007945",
"sha256": "b081b25d3ed80e6fb14012cd428e6b60c1ed7b77ce769f1510f73a2195a1f985",
"versions": [
"1.0.8"
],
"source": "amazon-inspector",
"modified_time": "2026-07-01T21:20:16Z"
},
{
"import_time": "2026-07-01T22:03:01.619286475Z",
"id": "IN-MAL-2026-007951",
"sha256": "ca6dd98e3ea21871ac47c5ff8e0bdacad9543caa8094c1a709666e559dd6cc29",
"modified_time": "2026-07-01T21:21:06Z",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
},
{
"import_time": "2026-07-01T22:03:01.517320725Z",
"id": "IN-MAL-2026-007950",
"sha256": "f3318b0646ee273862994f3f82e9f10f5509bad27643f60d737407751819e3eb",
"modified_time": "2026-07-01T21:20:58Z",
"source": "amazon-inspector",
"versions": [
"1.0.7"
]
},
{
"import_time": "2026-07-01T22:03:01.469652495Z",
"id": "IN-MAL-2026-007949",
"sha256": "35d8ec9fe8175187d954aa5990d138efda2b727b12a014cda50cdc094a0241c5",
"modified_time": "2026-07-01T21:20:49Z",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
},
{
"import_time": "2026-07-01T22:03:01.199460609Z",
"id": "IN-MAL-2026-007943",
"sha256": "8d10a0d7bcaa1ec28f749d4cb493ce930f7c59d2b59a627cf1443ebf6e5ed26e",
"modified_time": "2026-07-01T21:20:00Z",
"source": "amazon-inspector",
"versions": [
"1.0.12"
]
},
{
"import_time": "2026-07-01T22:03:01.424377839Z",
"id": "IN-MAL-2026-007948",
"sha256": "980ccf3d2bcf2e7571c3ce0302f1c8a32667e3f57f0b49c2a2dd7b7bfc02fa28",
"modified_time": "2026-07-01T21:20:41Z",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
},
{
"import_time": "2026-07-05T23:26:10.593466544Z",
"sha256": "7c5de26d6b059360fd9639f3fa4545a86a377e44d5b158d03ec80a5ba47c4771",
"modified_time": "2026-07-01T13:36:02Z",
"source": "ossf-package-analysis",
"versions": [
"1.0.11"
]
},
{
"import_time": "2026-07-05T23:26:10.750171243Z",
"sha256": "86c54a7b7440119b5dd110c057a11c88fd8b31ad75aca7bf3952a84db3a79a69",
"versions": [
"1.0.6"
],
"source": "ossf-package-analysis",
"modified_time": "2026-07-01T12:21:14Z"
},
{
"import_time": "2026-07-05T23:26:10.675640787Z",
"sha256": "ce1ca649ed328e42fb7d574f795747c1e05ee7b6a0f246d44808a4c50886366e",
"modified_time": "2026-07-01T13:25:50Z",
"source": "ossf-package-analysis",
"versions": [
"1.0.10"
]
},
{
"import_time": "2026-07-20T13:14:45.541549633Z",
"id": "RLMA-2026-05527",
"sha256": "5b3475c99da00a488ce9ad9416a4489cadffdc87cbdcd3d86fe2630ad10b54c8",
"modified_time": "2026-07-20T10:39:10Z",
"source": "reversing-labs",
"versions": [
"1.0.5"
]
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/date-fns-lite/MAL-2026-6722.json"
{
"evidence_files": [
{
"path": "postinstall.js",
"tlsh": "acf197657afb21245a6ad4eaa28f21123510f50b3e04ce94766c47d0bf8a0b8b6773dd",
"sha256": "e3f0715ac3e04524b506c4d4a2c3c876a1337bb0c5e845b0d222712472662abf"
},
{
"path": "package.json",
"tlsh": "1be06830082259232ac587e6ed220e477d200d23025cbc1823e3512883ceb7b98fd22e",
"sha256": "d44e4fd7032afcb424ecab971c0d90eed6229f25996ef9af99955630fcfb74d8"
}
],
"package_integrity": [
{
"filename": "date-fns-lite-1.0.5.tgz",
"hashes": {
"sha512_sri": "sha512-SjGJX0jgJh+dSAy7IFbltbuap26Qn1Y/Iz/43jG3Zc3+0hILPcp8ut7rdXnl5LQpdIwecWhrOvDsOHHp5ZQy6Q==",
"sha1": "1f6ba05d374fbacf04a92f6fb913fe6231224b39"
}
}
]
}