Malicious code in date-format-utils-xz (npm)
The npm package date-format-utils-xz versions 1.0.3 and 1.0.4 contains malicious code that executes automatically upon installation. The postinstall.js script performs host reconnaissance commands and collects environment variables, including potential CI/build secrets. It also queries cloud instance metadata endpoints for AWS, Aliyun, and Tencent Cloud to harvest temporary IAM/role credentials. The collected data is sent unencrypted to a hardcoded external IP address. The package is disguised as a legitimate date-formatting utility but is confirmed malicious by internal comments.
AI Analysis
Technical Summary
The date-format-utils-xz npm package versions 1.0.3 and 1.0.4 include a postinstall.js script that runs automatically during npm install. This script executes system commands (hostname, whoami, id, env, ifconfig, ls /, /proc/1/cgroup) to gather host information and environment variables, potentially exposing sensitive CI/build secrets. It then queries cloud metadata services at 169.254.169.254 for AWS, Aliyun, and Tencent Cloud to obtain temporary credentials. The aggregated data is sent via an unencrypted HTTP POST request to a hardcoded IP address (8.135.48.40) at the path /meta/all. A comment in the code explicitly states the package is disguised as a normal date-formatting tool, confirming its malicious intent.
Potential Impact
Installation of affected versions results in unauthorized execution of reconnaissance commands and exfiltration of sensitive environment variables and cloud instance credentials. This can lead to credential compromise, unauthorized access to cloud resources, and potential further exploitation of the affected environment. The exposure of CI/build secrets increases the risk of supply chain attacks or unauthorized code modifications.
Mitigation Recommendations
Avoid using the date-format-utils-xz package versions 1.0.3 and 1.0.4. Since no patch or remediation is currently available, remove these versions from your projects and dependency trees. Monitor for any usage of this package and replace it with a trusted alternative. Conduct a security review of environments where these versions were installed to assess potential credential exposure and rotate any compromised secrets or credentials. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates on remediation.
Malicious code in date-format-utils-xz (npm)
Description
The npm package date-format-utils-xz versions 1.0.3 and 1.0.4 contains malicious code that executes automatically upon installation. The postinstall.js script performs host reconnaissance commands and collects environment variables, including potential CI/build secrets. It also queries cloud instance metadata endpoints for AWS, Aliyun, and Tencent Cloud to harvest temporary IAM/role credentials. The collected data is sent unencrypted to a hardcoded external IP address. The package is disguised as a legitimate date-formatting utility but is confirmed malicious by internal comments.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The date-format-utils-xz npm package versions 1.0.3 and 1.0.4 include a postinstall.js script that runs automatically during npm install. This script executes system commands (hostname, whoami, id, env, ifconfig, ls /, /proc/1/cgroup) to gather host information and environment variables, potentially exposing sensitive CI/build secrets. It then queries cloud metadata services at 169.254.169.254 for AWS, Aliyun, and Tencent Cloud to obtain temporary credentials. The aggregated data is sent via an unencrypted HTTP POST request to a hardcoded IP address (8.135.48.40) at the path /meta/all. A comment in the code explicitly states the package is disguised as a normal date-formatting tool, confirming its malicious intent.
Potential Impact
Installation of affected versions results in unauthorized execution of reconnaissance commands and exfiltration of sensitive environment variables and cloud instance credentials. This can lead to credential compromise, unauthorized access to cloud resources, and potential further exploitation of the affected environment. The exposure of CI/build secrets increases the risk of supply chain attacks or unauthorized code modifications.
Mitigation Recommendations
Avoid using the date-format-utils-xz package versions 1.0.3 and 1.0.4. Since no patch or remediation is currently available, remove these versions from your projects and dependency trees. Monitor for any usage of this package and replace it with a trusted alternative. Conduct a security review of environments where these versions were installed to assess potential credential exposure and rotate any compromised secrets or credentials. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates on remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-11001
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a6150ee9c2644c7f8da2d20
Added to database: 07/22/2026, 23:23:26 UTC
Last enriched: 07/22/2026, 23:42:45 UTC
Last updated: 07/22/2026, 23:42:45 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.