Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

datefmt-helpernpm

Advisory published Updated

datefmt-helper is a confirmed malicious npm package (MAL-2026-6788) that typosquats a legitimate package to trick installs (malicious versions 1.0.0, 1.0.1). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in datefmt-helper (npm)

MAL-2026-6788
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall datefmt-helper

What this malware does

The npm package datefmt-helper is a supply-chain dropper disguised as a benign date-formatting utility (its description reads "dates formatting utility with locale support"). The package ships no source repository and places its real behaviour in an install script.

A postinstall lifecycle hook (postinstall: node postinstall.js) executes automatically on npm install, before the package is ever imported. The install script uses HTTP / curl / wget primitives to download a second-stage payload from the hardcoded external IP 115.190.124.243, then executes it via a Node child process — the classic download-and-execute pattern. Any developer workstation or CI runner that installs the package (directly or transitively) hands arbitrary code execution to the operator of that endpoint.

On npm install, the package's postinstall script fetches an unauthenticated payload over plain HTTP from a hardcoded bare IP (115.190.124.243:8761) and executes it. On Unix, curl/wget output is piped directly to sh. On Windows, certutil.exe -urlcache -split -f downloads a batch file to C:\Users\Public\run.bat and executes it. The fetched content is unpinned, unverified, and mutable — the operator of the endpoint can serve arbitrary code at any time. The package advertises itself as a lightweight date formatter (date-fns-lite branding, impersonating the date-fns ecosystem), but the payload has no relationship to date formatting. The typosquat/impersonation branding combined with an install-time dropper is a supply-chain attack lure.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

2 flagged
1.0.01.0.1

Indicators of compromise (SHA-256)

3d7f5d0b1ca6df789353a5558b55adc3da08246c73ad0d1aba92f7321b4afec2
d92b853245953aa75db608f0ae2e5de2321301b94ca6b48f55746a1bd60b6ea4
6c9b82c471edb6b2caeb78c78887556e4c313efc0ba29a88a482b0f93d378807

Detection & response playbook

Typosquat
  1. Find it

    Search your lockfiles and build artifacts for datefmt-helper (2 malicious versions).

  2. If you installed it — respond

    datefmt-helper is a typosquat — you almost certainly intended a legitimately-named package. Remove datefmt-helper, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.

  3. Did it already run?

    If datefmt-helper was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. datefmt-helper on npm has been identified as a malicious package (versions 1.0.0, 1.0.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-008600IN-MAL-2026-009286GHSA-ch48-496p-pfv8

References

Credits

  • Amazon Inspector · finder
  • codelake Research · finder

Detect & block this

O3 blocks datefmt-helper-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore