OpenSSF/OSV advisory MAL-2026-11544 confirms this npm version as malicious. On npm install, package.json's postinstall hook launches a detached bash reverse shell over /dev/tcp to 124.221.154.135:4444, giving remote interactive control of the installer's host. A companion postinstall.js reads the installer's ~/.ssh directory listing along with os.userInfo() and platform data and POSTs the collected data over HTTPS to the same host 124.221.154.135...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in simple-date-formatter-util-10 (npm)
Details
On npm install, package.json's postinstall hook launches a detached bash reverse shell over /dev/tcp to 124.221.154.135:4444, giving remote interactive control of the installer's host. A companion postinstall.js reads the installer's ~/.ssh directory listing along with os.userInfo() and platform data and POSTs the collected data over HTTPS to the same host 124.221.154.135. Both mechanisms fire automatically at install time with no user interaction and provide the operator persistent remote access plus credential-material reconnaissance.
Decision reason
OpenSSF Malicious Packages via OSV confirms simple-date-formatter-util-10@1.0.0 as malicious (MAL-2026-11544): Malicious code in simple-date-formatter-util-10 (npm)