OpenSSF/OSV advisory MAL-2026-17161 confirms this npm version as malicious. The package's package.json postinstall script curls cloud instance-metadata endpoints (AWS IMDS at 169.254.169.254/latest/meta-data/sts-credential, Alibaba/Tencent metadata at metadata.tencentyun.com and 169.254.0.23) into /tmp files and POSTs their concatenated contents plus `ls -la /data/` output to a remote collector (placeholder host YOUR_BURP_SERVER). The tarball additionally ships postinstall.js containing...
This report applies to simple-date-formatter-new-15@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.