OpenSSF/OSV advisory MAL-2026-17229 confirms this npm version as malicious. npm package simple-date-formatter-new-12@1.0.0 declares a postinstall lifecycle script in package.json that runs automatically on `npm install`. The script uses curl to fetch an internal Baidu host (http://bsrc-ssrf.n.baidu-int.com/...), writes the response to /tmp/bsrc.txt, and POSTs the contents to an attacker-controlled interactsh collector at pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun/bsrc...
This report applies to simple-date-formatter-new-12@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.