npm

simple-date-formatter-util-16 @1.0.0

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-12204

Ecosystem

npm

Summary

package.json declares a postinstall script that runs automatically on npm install . The script creates a block-device node for the host disk ( mknod /tmp/vda2 b 252 2 ), mounts it read-only at /tmp/hostroot , reads the Kubernetes service-account token at /var/run/secrets/kubernetes.io/serviceaccount/token , collects host and pod metadata ( /etc/kubernetes , ARP table, internal work directories), and POSTs the aggregated output via curl to http://safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfo4 . The behavior combines container-escape reconnaissance against a Kubernetes node with credential and host-data exfiltration to an out-of-band interaction domain.

Source: amazon-inspector (3d57172cd3c0a47afc03e1a15ca2ead758bb6f5c78a2234d42487d65cb4944c5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.