Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

datetime-toolkitnpm

datetime-toolkit is a confirmed malicious npm package (MAL-2026-5611) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.1, 1.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in datetime-toolkit (npm)

MAL-2026-5611
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall datetime-toolkit

What this malware does

The package presents itself as a lightweight datetime utility but its main entry datetime.js invokes collect() from ./index.js at top level, so any require('datetime-toolkit') or import immediately triggers exfiltration. collect() serializes the entire process.env, the machine hostname, and a timestamp, AES-256-GCM-encrypts the JSON with a hardcoded key, and POSTs the result over plain HTTP to http://20.160.234.175:5000/collect. Strings and identifiers throughout index.js are obfuscated: the destination URL is built from \uXXXX escapes, the bearer token and encryption key are reverse-string literals ('nekot-terces'secret-token, 'yek-noitpyrcne-tikloot-emitetad'datetime-toolkit-encryption-key), and core APIs (http, crypto, os, process.env, POST, Authorization) are unicode-escaped. The package additionally ships a bin (cli.js) that runs the same collector behind a 'Collecting and sending…' spinner. The benign datetime/React helpers are a cover story; importing the package leaks CI secrets, cloud credentials, source tokens, and database passwords from any installer that loads it.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

8 flagged
1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.7

Indicators of compromise (SHA-256)

0dc38777296d43cff21c9e56d16208c8925c6dc25b5dec4227823da94096433d
7724b8aace8cd3648792d8094d9434e47daff353c137b9df03849dd3a22b4943
7d997e277a4f73cc68d97e58d8296a07af2ff574861d1277634d628b27187488
9cabde708bb395da5b87359c85472f1bff9da7e46e1881cad07c247a80ab9ff3
b312f9578e0376e86e5e623507841aea7c580b6dd906795b9c2eacc90f75f40e
09550789b072ef4495603e59afe2f2f7cfe4c0c3283fafc1f2c497f2cb3e8820
09cb23aa526bb73decd054c5367bcbc478550eedc493c255cc7bf257c8a727d5
2584500ccf0f5a2a68a6498f4be399813c946463e721cf2e7716a5a7216c9e11
6c0bbf5bcbd2bda55a0d08b905d017e2ef718d85a9c40a6fd4039cc97090c2e6

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for datetime-toolkit (8 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging datetime-toolkit across your stack and pipelines.

  2. If you installed it — respond

    datetime-toolkit is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If datetime-toolkit was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks datetime-toolkit before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. datetime-toolkit on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-005700IN-MAL-2026-005861GHSA-hjx5-46c8-fm8pIN-MAL-2026-018445IN-MAL-2026-018442IN-MAL-2026-018448IN-MAL-2026-018438IN-MAL-2026-018440IN-MAL-2026-018444

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks datetime-toolkit-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

datetime-toolkit (npm) malicious package — MAL-2026-5611 | O3 Security