simple-date-formatter-new-12@1.0.0
Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 8:08 PM UTC
OSV ID
MAL-2026-17229
Ecosystem
npm
Summary
npm package simple-date-formatter-new-12@1.0.0 declares a postinstall lifecycle script in package.json that runs automatically on npm install. The script uses curl to fetch an internal Baidu host (http://bsrc-ssrf.n.baidu-int.com/...), writes the response to /tmp/bsrc.txt, and POSTs the contents to an attacker-controlled interactsh collector at pdxkwzizhzzdpzpgcieqk6d1v7ynqsgfo.oast.fun/bsrc. The package's advertised purpose is a trivial date-formatting wrapper (index.js exports a single formatDate function); the SSRF probe and outbound exfiltration are unrelated to that purpose. The name shape (simple-date-formatter-new-12), empty author metadata, and OAST beacon are consistent with a dependency-confusion / typosquat probe designed to detect installation inside a target organization and leak internal network responses reachable from the installer's network position to a third-party collector.
Source: amazon-inspector (bd79db99adb8878673dd85db5a29661432808fa8fcc5e3d750b907418df8ae5f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.