date-format-utils-xz@1.0.4
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-11001
Ecosystem
npm
Summary
The package presents itself as a date-formatting utility but its postinstall.js runs automatically on npm install and performs credential/metadata theft. It shells out via execSync/curl to query cloud instance metadata endpoints for Alibaba Cloud (100.100.100.200), AWS (169.254.169.254), and Tencent (metadata.tencentyun.com), dumps the installer's entire process environment (env > /tmp/env.txt), and POSTs each payload to a hardcoded bare-IP server at http://8.135.48.40 (path /meta/env for the env dump). A GET fallback exfiltrates error details to the same host. index.js is a minimal date-utility stub and contains a comment ("disguised as a normal date formatting tool") acknowledging the cover, while the exfiltration logic lives entirely in the postinstall lifecycle script. On any cloud or CI host, this leaks whatever secrets are present in the environment (AWS_*, tokens, DB passwords, CI secrets) and any credentials retrievable from the instance metadata services.
Source: amazon-inspector (51816185297e91d0ce1b3b63c53ed946db64bebcb353898df580d8302b54773f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.