{"id":"MAL-2026-12032","summary":"Malicious code in add-two-numbers-x7q9m (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (550dfc48a74577d95e53fc64cc296a9cc59a5940edb6eac3f191f41376350635)\nThe package advertises itself as a trivial 'add two numbers' utility but its preinstall lifecycle script enumerates the installer's Desktop directory, reads.txt files, applies a regex (/npm_[A-Za-z0-9_-]+/) to extract npm authentication tokens, and transmits any match as a query parameter to the hardcoded endpoint https://lively-bird-15.webhook.cool. This runs automatically on `npm install`. The behavior has no relation to the package's advertised arithmetic functionality, and the random name suffix is consistent with a disposable malicious-publish account. Harvested npm tokens enable registry account takeover and downstream supply-chain propagation via the victim's publish rights.\n","modified":"2026-08-05T14:35:11.572162522Z","published":"2026-08-05T01:00:50Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T01:39:30.817175254Z","modified_time":"2026-08-05T01:00:50Z","sha256":"550dfc48a74577d95e53fc64cc296a9cc59a5940edb6eac3f191f41376350635","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-011479"},{"id":"IN-MAL-2026-014922","import_time":"2026-08-05T14:19:43.232813305Z","modified_time":"2026-08-05T13:12:06Z","sha256":"2ec8df5e22704e01dbe83cb2b85e111a1d796cf84f04caa4c56c536678795cd4","source":"amazon-inspector","versions":["1.0.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/add-two-numbers-x7q9m/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/add-two-numbers-x7q9m/v/1.0.1"}],"affected":[{"package":{"name":"add-two-numbers-x7q9m","ecosystem":"npm","purl":"pkg:npm/add-two-numbers-x7q9m"},"versions":["1.0.0","1.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/add-two-numbers-x7q9m/MAL-2026-12032.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"1e2b721d5a878cf9c11fea78812f8655b88c0125d10afcb9b413d7e21a410643","tlsh":"2a110ee5cde82134b77160d48e072c1f759fce623e82c981c25c19a623d4d484a9aebe","path":"scripts/preinstall.js"},{"sha256":"fe63e3808f096865c61e424761b12f66f3c9649e7b4a6d6879b3df77131740c8","tlsh":"96f08220cc115e6324c45b925d76564665a24a2b45187c1837c3503c8f9f36f24ff55e","path":"package.json"}],"package_integrity":[{"hashes":{"sha1":"23226ba1e2b5fd74458201b17ae943d29cd318c9","sha512_sri":"sha512-1Inft9bgCUfN6bBUuap1+WzTwDP4afyNU7yZ7MlblQmM7XwymZ+kTaFIGg+zVuI8odgTI8jd0E1aCjlFHk7kGQ=="},"filename":"add-two-numbers-x7q9m-1.0.0.tgz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}