Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in datetime-fmt-xutil (npm)

0
Critical
Published: 08/13/2026 (08/13/2026, 14:59:12 UTC)
Source: GCVE Database
Product: datetime-fmt-xutil

Description

The npm package datetime-fmt-xutil version 1.0.0 contains malicious code in its postinstall.js script. This script opens a TCP connection to a hardcoded IP address and pipes a shell to the remote endpoint, granting interactive shell access to an attacker. The malicious behavior executes unconditionally during npm install and uses fallback methods with bash and python3 to establish the reverse shell. Failures are reported via HTTP GET requests to the attacker's server. The package's legitimate date-formatting functionality is a cover for this reverse-shell payload.

Affected software

npmghsa
datetime-fmt-xutil
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 18:08:32 UTC

Technical Analysis

The npm package datetime-fmt-xutil version 1.0.0 includes a postinstall.js script that, upon installation, opens a TCP connection to the hardcoded IP 8.135.48.40 on port 4444. It pipes the standard input/output of /bin/sh through this socket, effectively granting the remote operator interactive shell access on the installer's machine. If the primary method fails, it attempts to spawn a shell using bash or python3 one-liners. Any failure in establishing the shell connection is beaconed back to the attacker via HTTP GET requests. This malicious behavior is unconditional and triggered automatically during npm install, with the package's date-formatting code serving as a disguise for the reverse shell payload. The hardcoded IP is unrelated to the declared publisher, indicating a supply chain compromise or malicious package upload.

Potential Impact

Successful installation of this package version results in the attacker gaining remote interactive shell access on the victim's machine. This allows full control over the system with the privileges of the user running npm install, potentially leading to data theft, system compromise, or further malware deployment. The unconditional execution during installation increases the risk of widespread compromise if the package is used.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately avoid installing datetime-fmt-xutil version 1.0.0. Remove any installations of this package from systems and audit affected environments for signs of compromise. Use trusted package sources and verify package integrity before installation. Monitor for updates from the package maintainer or npm security advisories for any official fixes or removals. Patch status is not yet confirmed — check the vendor advisory or npm security channels for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13935
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7e036ebf8831d5398f9039

Added to database: 08/13/2026, 17:48:30 UTC

Last enriched: 08/13/2026, 18:08:32 UTC

Last updated: 08/13/2026, 19:11:12 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses