VYPR

npm · Malicious package advisory

Malware

simple-date-formatter-new-12

MAL-2026-17229

Malicious code in simple-date-formatter-new-12 (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (bd79db99adb8878673dd85db5a29661432808fa8fcc5e3d750b907418df8ae5f)
npm package [email protected] declares a postinstall lifecycle script in package.json that runs automatically on `npm install`. The script uses curl to fetch an internal Baidu host (http://bsrc-ssrf.n.baidu-int.com/...), writes the response to /tmp/bsrc.txt, and POSTs the contents to an attacker-controlled interactsh collector at pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun/bsrc. The package's advertised purpose is a trivial date-formatting wrapper (index.js exports a single formatDate function); the SSRF probe and outbound exfiltration are unrelated to that purpose. The name shape (`simple-date-formatter-new-12`), empty author metadata, and OAST beacon are consistent with a dependency-confusion / typosquat probe designed to detect installation inside a target organization and leak internal network responses reachable from the installer's network position to a third-party collector.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.