Malicious code in simple-date-formatter-util-5 (npm)
The npm package simple-date-formatter-util-5 version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.
- Disclosed
- Last updated
- Blast radius
- All npm users who installed simple-date-formatter-util-5 version 1.0.0
- Ecosystems
- Attack vectors
- Affected entities
- simple-date-formatter-util-5 · 1.0.0
The OpenSSF Package Analysis project identified simple-date-formatter-util-5 version 1.0.0 on npm as a malicious package. Analysis revealed that the package contains code designed to communicate with domains associated with malicious activity and execute commands associated with malicious behavior.\n\nThe package was flagged through the OpenSSF's malicious-packages repository, which maintains a catalog of confirmed malicious packages across package ecosystems. The malicious behavior was detected through static and dynamic analysis of the package contents.\n\nAny system that installed this specific version of the package may have been compromised. The package appears to have been published with the intent to distribute malware to npm users.
Indicators of compromise
- Packages
- simple-date-formatter-util-5@1.0.0
Remediation
- Immediately uninstall simple-date-formatter-util-5 version 1.0.0 from all systems
- Remove the package from package.json and lock files
- Run a full security audit on affected systems for signs of compromise
- Review system logs for suspicious network connections or command execution
- Consider using alternative date formatting libraries from trusted sources
- Monitor npm for any related malicious packages with similar names
Sources
- GitHub Advisory GHSA-rhm2-fwx3-922c · GitHub Advisory Database
Cite this entry
"Malicious code in simple-date-formatter-util-5 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 3, 2026; last updated August 3, 2026. https://supplychainattack.org/incident/malicious-code-in-simple-date-formatter-util-5-npm-1se8q6
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @types-beta/sdk (npm)
The npm package @types-beta/sdk (versions 0.1.0–0.1.3) is a supply-chain dropper that impersonates the trusted @types/DefinitelyTyped namespace. It bundles a Windows executable (nanocache.exe) that executes at import time, establishing a persistent remote-access agent with command-and-control capabilities.
npmCompromised packageTyposquatting - containedcritical
Malware in fluid-type-ui
Malware was discovered in the npm package fluid-type-ui. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in accounts-loading-state
The npm package accounts-loading-state was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.
npmCompromised package - containedcritical
Malware in lifestyle-test-utils
Malware was discovered in the npm package lifestyle-test-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package