🛡️ MAL-2026-12196 — simple-date-formatter-new-4

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in simple-date-formatter-new-4 (npm)

Source: amazon-inspector

Package advertises itself as a date-formatting utility but its actual behavior on install is credential theft and internal-network reconnaissance. The postinstall script in package.json runs a shell one-liner that probes internal Kubernetes API endpoints, dumps /etc/resolv.conf and ip route, TCP-scans internal hosts, reads the pod's Kubernetes service-account token from /var/run/secrets/kubernetes.io/serviceaccount/token, and POSTs the aggregated output via curl to a hardcoded OAST (interact.sh) collector at http://safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo8. A bundled postinstall.js additionally enumerates ~/.ssh (listing public keys), collects the local username and platform, and POSTs the JSON to a hardcoded IP 124.221.154.135 over HTTPS; in-file comments describe it as an SSH-key theft C2 demo. The library payload (index.js) is a three-line wrapper around toLocaleDateString, functioning solely as cover for the install-time attack.

Affected software

MAL-2026-12196 is recorded against 1 package.

  • simple-date-formatter-new-4

Timeline and source

Published on 5 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.npmjs.com (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-08-05
Updated 2026-08-12
Modified 2026-08-05
Fix URL N/A

Affected Packages

Software From version Fixed in
simple-date-formatter-new-4

Free Vulnerability Check

Is your site affected by MAL-2026-12196?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-12196 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.