OpenSSF/OSV advisory MAL-2026-15974 confirms this npm version as malicious. The package impersonates the popular date-fns library. Its main module, date-fns-formatter.js, contains a small formatDate shim as a decoy in front of a heavily obfuscated IIFE (obfuscator.io-style rotated string array with a runtime decoder) that runs whenever the module is required. The IIFE creates a hidden directory under os.homedir(), writes a package.json declaring axios, better-sqlite3, node-machine-id, and...
This report applies to date-fns-formatter@1.3.10.
1.3.10, 1.3.8, 1.3.9, 1.4.9
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.