Malicious code in datetime-toolkit (npm)
The npm package 'datetime-toolkit' is a malicious package that exfiltrates sensitive environment data immediately upon being imported or required. It encrypts and sends process environment variables, machine hostname, and timestamps to a remote server over unencrypted HTTP. The package uses obfuscation techniques to hide its malicious behavior. Installing or running this package compromises the host machine, risking exposure of secrets such as CI credentials, cloud keys, source tokens, and database passwords.
AI Analysis
Technical Summary
The 'datetime-toolkit' npm package masquerades as a lightweight datetime utility but contains malicious code in its main entry point 'datetime.js' that triggers data exfiltration on import. It calls a 'collect()' function that serializes the entire process environment, hostname, and timestamp, encrypts this data using AES-256-GCM with a hardcoded key, and sends it via HTTP POST to a remote IP address. The code uses Unicode escapes and reversed string literals to obfuscate critical strings such as the destination URL, bearer token, and encryption key. The package also includes a CLI that performs the same data collection and exfiltration. This results in leakage of sensitive secrets and credentials from any system that installs or runs this package.
Potential Impact
Systems that install or run the 'datetime-toolkit' package are fully compromised as the package exfiltrates environment variables and secrets including CI secrets, cloud credentials, source tokens, and database passwords. This exposure can lead to unauthorized access to cloud resources, source code repositories, databases, and other critical infrastructure. Because the package sends data over unencrypted HTTP, interception is also possible. Removal of the package alone may not fully remediate the compromise as attackers may have established persistence.
Mitigation Recommendations
Remove the 'datetime-toolkit' package immediately from all affected systems. Rotate all secrets, credentials, and keys that were stored or accessible on compromised machines using a separate, secure environment. Because the package grants attackers full control, assume the system is compromised and perform a thorough incident response including forensic analysis and system rebuild if necessary. No official patch or fix is available; the package itself is malicious and should be avoided entirely.
Malicious code in datetime-toolkit (npm)
Description
The npm package 'datetime-toolkit' is a malicious package that exfiltrates sensitive environment data immediately upon being imported or required. It encrypts and sends process environment variables, machine hostname, and timestamps to a remote server over unencrypted HTTP. The package uses obfuscation techniques to hide its malicious behavior. Installing or running this package compromises the host machine, risking exposure of secrets such as CI credentials, cloud keys, source tokens, and database passwords.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'datetime-toolkit' npm package masquerades as a lightweight datetime utility but contains malicious code in its main entry point 'datetime.js' that triggers data exfiltration on import. It calls a 'collect()' function that serializes the entire process environment, hostname, and timestamp, encrypts this data using AES-256-GCM with a hardcoded key, and sends it via HTTP POST to a remote IP address. The code uses Unicode escapes and reversed string literals to obfuscate critical strings such as the destination URL, bearer token, and encryption key. The package also includes a CLI that performs the same data collection and exfiltration. This results in leakage of sensitive secrets and credentials from any system that installs or runs this package.
Potential Impact
Systems that install or run the 'datetime-toolkit' package are fully compromised as the package exfiltrates environment variables and secrets including CI secrets, cloud credentials, source tokens, and database passwords. This exposure can lead to unauthorized access to cloud resources, source code repositories, databases, and other critical infrastructure. Because the package sends data over unencrypted HTTP, interception is also possible. Removal of the package alone may not fully remediate the compromise as attackers may have established persistence.
Defensive Guidance
Remove the 'datetime-toolkit' package immediately from all affected systems. Rotate all secrets, credentials, and keys that were stored or accessible on compromised machines using a separate, secure environment. Because the package grants attackers full control, assume the system is compromised and perform a thorough incident response including forensic analysis and system rebuild if necessary. No official patch or fix is available; the package itself is malicious and should be avoided entirely.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-5611
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-hjx5-46c8-fm8p"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a870a73acd9273b49b58aa5
Added to database: 08/20/2026, 14:08:51 UTC
Last enriched: 08/20/2026, 14:30:29 UTC
Last updated: 08/20/2026, 14:30:29 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.