time-utils-helper@1.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 12:33 PM UTC
OSV ID
MAL-2026-12225
Ecosystem
npm
Summary
The package advertises itself as a time-formatting utility (index.js exports formatDate/capitalize/truncate) but ships a postinstall.js lifecycle script that runs on npm install and performs unrelated cloud credential harvesting. postinstall.js uses child_process.exec to shell out to curl against multi-cloud instance metadata services (AWS 169.254.169.254, Aliyun 100.100.100.200, Tencent metadata.tencentyun.com, GCP metadata.google.internal, Azure), extracts AWS IAM security credentials for the instance role into /tmp/.iam-creds, and transmits hostname, user, and the IAM credential material as HTTP GET query-string parameters to the hardcoded Burp Collaborator subdomain pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com. The mismatch between the declared trivial utility purpose and the install-time cloud-metadata scraping identifies the package as a decoy delivery vehicle for credential theft.
Source: amazon-inspector (93cbd818e3b29b2b7c9da6f48b3d82baae1af9bd0fa637a2848749bdfea86084)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.