🛡️ MAL-2026-12196 — simple-date-formatter-new-4
Description
Malicious code in simple-date-formatter-new-4 (npm)
Source: amazon-inspector
Package advertises itself as a date-formatting utility but its actual behavior on install is credential theft and internal-network reconnaissance. The postinstall script in package.json runs a shell one-liner that probes internal Kubernetes API endpoints, dumps /etc/resolv.conf and ip route, TCP-scans internal hosts, reads the pod's Kubernetes service-account token from /var/run/secrets/kubernetes.io/serviceaccount/token, and POSTs the aggregated output via curl to a hardcoded OAST (interact.sh) collector at http://safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo8. A bundled postinstall.js additionally enumerates ~/.ssh (listing public keys), collects the local username and platform, and POSTs the JSON to a hardcoded IP 124.221.154.135 over HTTPS; in-file comments describe it as an SSH-key theft C2 demo. The library payload (index.js) is a three-line wrapper around toLocaleDateString, functioning solely as cover for the install-time attack.
Affected software
MAL-2026-12196 is recorded against 1 package.
- simple-date-formatter-new-4
Timeline and source
Published on 5 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| simple-date-formatter-new-4 | — | — |
References
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-12196?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-12196 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.