Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

datefmt-helpernpm

datefmt-helper is a confirmed malicious npm package (MAL-2026-6788) that typosquats a legitimate package to trick installs (malicious versions 1.0.0, 1.0.1). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in datefmt-helper (npm)

MAL-2026-6788
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall datefmt-helper

What this malware does

The npm package datefmt-helper is a supply-chain dropper disguised as a benign date-formatting utility (its description reads "dates formatting utility with locale support"). The package ships no source repository and places its real behaviour in an install script.

A postinstall lifecycle hook (postinstall: node postinstall.js) executes automatically on npm install, before the package is ever imported. The install script uses HTTP / curl / wget primitives to download a second-stage payload from the hardcoded external IP 115.190.124.243, then executes it via a Node child process — the classic download-and-execute pattern. Any developer workstation or CI runner that installs the package (directly or transitively) hands arbitrary code execution to the operator of that endpoint.

Detected and classified independently by codelake Research from the live npm feed on 2026-07-02; at the time of reporting the package was not present in OSV or GHSA (a first-catch).

On npm install, the package's postinstall script fetches an unauthenticated payload over plain HTTP from a hardcoded bare IP (115.190.124.243:8761) and executes it. On Unix, curl/wget output is piped directly to sh. On Windows, certutil.exe -urlcache -split -f downloads a batch file to C:\Users\Public\run.bat and executes it. The fetched content is unpinned, unverified, and mutable — the operator of the endpoint can serve arbitrary code at any time. The package advertises itself as a lightweight date formatter (date-fns-lite branding, impersonating the date-fns ecosystem), but the payload has no relationship to date formatting. The typosquat/impersonation branding combined with an install-time dropper is a supply-chain attack lure.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

2 flagged
1.0.01.0.1

Indicators of compromise (SHA-256)

3d7f5d0b1ca6df789353a5558b55adc3da08246c73ad0d1aba92f7321b4afec2
d92b853245953aa75db608f0ae2e5de2321301b94ca6b48f55746a1bd60b6ea4
6c9b82c471edb6b2caeb78c78887556e4c313efc0ba29a88a482b0f93d378807

Detection & response playbook

Typosquat
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for datefmt-helper (2 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging datefmt-helper across your stack and pipelines.

  2. If you installed it — respond

    datefmt-helper is a typosquat — you almost certainly intended a legitimately-named package. Remove datefmt-helper, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.

  3. Did it already run?

    If datefmt-helper was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks datefmt-helper before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. datefmt-helper on npm has been identified as a malicious package (versions 1.0.0, 1.0.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-008600IN-MAL-2026-009286GHSA-ch48-496p-pfv8

References

Credits

  • Amazon Inspector · finder
  • codelake Research · finder

Detect & block this

O3 blocks datefmt-helper-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

datefmt-helper (npm) malicious package — MAL-2026-6788 | O3 Security