VYPR

npm · Malicious package advisory

Malware

simple-date-formatter-new-12

GHSA-v6p6-9wrj-f56p

Malicious code in simple-date-formatter-new-12 (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (bd79db99adb8878673dd85db5a29661432808fa8fcc5e3d750b907418df8ae5f)
npm package [email protected] declares a postinstall lifecycle script in package.json that runs automatically on `npm install`. The script uses curl to fetch an internal Baidu host (http://bsrc-ssrf.n.baidu-int.com/...), writes the response to /tmp/bsrc.txt, and POSTs the contents to an attacker-controlled interactsh collector at pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun/bsrc. The package's advertised purpose is a trivial date-formatting wrapper (index.js exports a single formatDate function); the SSRF probe and outbound exfiltration are unrelated to that purpose. The name shape (`simple-date-formatter-new-12`), empty author metadata, and OAST beacon are consistent with a dependency-confusion / typosquat probe designed to detect installation inside a target organization and leak internal network responses reachable from the installer's network position to a third-party collector.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/9c4594ea270f8ce1185755115d5eb811c41d8589/osv/malicious/npm/simple-date-formatter-new-12/MAL-2026-17229.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/9c4594ea270f8ce1185755115d5eb811c41d8589/osv/malicious/npm/simple-date-formatter-new-12/MAL-2026-17229.json
- https://www.npmjs.com/package/simple-date-formatter-new-12/v/1.0.0
- https://github.com/advisories/GHSA-v6p6-9wrj-f56p

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.