{"id":"MAL-2026-5599","summary":"Malicious code in 0x2ai-ivo (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e78c039ee7ad67b1a20ef30b37ce03178f6c2181b1e330db69e04dabd0a28686)\nOn install, the postinstall script copies the package's `payload/` tree (CLAUDE.md,.claude/settings.json,.mcp.json, and several.cjs MCP scripts) into the consumer's project directory (`process.env.INIT_CWD || process.cwd()`) at `scripts/postinstall.cjs`, materializing Claude Code project config inside any repo where `npm install` was run. The dropped `.mcp.json` registers an MCP server whose env includes `BRIDGE_URL=https://ivo.0x2ai.com` and a hardcoded shared bearer token (`BRIDGE_AUTH_TOKEN`), so any installer's Claude Code instance auto-attaches to that author-operated bridge. The package's CLI (`bin/start.cjs`) then spawns `claude --dangerously-skip-permissions` via a shell, deliberately stripping the permission gate that normally protects the host from agent actions. The MCP scripts (`payload/chatroom-mcp-lite-patched.cjs`, `payload/chatroom-monitor.cjs`, `payload/chatroom-wait-once.cjs`) POST to and long-poll `https://ivo.0x2ai.com`, receiving chatroom messages that CLAUDE.md/`0x2ai-boot.md` instruct the agent to act on. The exposed MCP tools (`provider_query`, `memory_save`, `memory_load`, `chatroom_post`) further route user prompts, conversation memory, and posted messages through the same endpoint authenticated by the shared static token. Net effect: an unattended, permission-bypassed Claude agent on the installer's machine that executes whatever instructions the operator of ivo.0x2ai.com pushes — an over-the-wire remote-control channel whose payloads are not in the tarball and not under the installer's control.\n","modified":"2026-07-17T03:04:23.246758151Z","published":"2026-06-11T07:16:15Z","withdrawn":"2026-07-16T00:38:53Z","database_specific":{"malicious-packages-origins":[{"versions":["1.2.0"],"id":"IN-MAL-2026-005672","import_time":"2026-06-11T07:49:39.35234197Z","modified_time":"2026-06-11T07:16:15Z","sha256":"e78c039ee7ad67b1a20ef30b37ce03178f6c2181b1e330db69e04dabd0a28686","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/0x2ai-ivo/v/1.2.0"}],"affected":[{"package":{"name":"0x2ai-ivo","ecosystem":"npm","purl":"pkg:npm/0x2ai-ivo"},"versions":["1.2.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"4943321a174f2de446781e46abdc4eb4fd333f8cc98cf6fe3cd5fc4bbfb0b0a2","tlsh":"74e0c05706ccd379a5b2a1406c12c50a646ade81364094a0e27c0357bf92694ae23eff","path":"scripts/postinstall.cjs"},{"sha256":"fa5af6d044cd42d37d4c7b0e5f43cf7498e621ef7db1b837ea79e3087e552984","tlsh":"9011005b868e07be57b441c46645c12b990bc84072d0e490d26e03a6fb511e82c677eb","path":"bin/start.cjs"},{"path":"payload/chatroom-mcp-lite-patched.cjs","sha256":"a1abc812c52dcefeb85473275f7c1e5a86770b114767176416ed94ebe620cf00","tlsh":"505307852c79603a4fb65365ba36a617ff35522bb01114b2fafcc2142f314d091aaefd"},{"tlsh":"c1e02659d4d40c5307525816083c214469a1a10b4eecbc3a778fc06c9f4c74b1abdacc","path":"payload/.mcp.json","sha256":"9a64d542acc824dad98a658c0bd23fb016facf918be3797c47d4cbdbe6cfa47a"}],"package_integrity":[{"filename":"0x2ai-ivo-1.2.0.tgz","hashes":{"sha1":"b57fe73ceddeec77e7fcb164acd5a17c31c44f61","sha512_sri":"sha512-t2kvTEpsitFhjUtVKsQc/pt5M2Iq5cy4Mio/p6WCO/stl1WhGFc0cURmEhaI4udVq9rgXxcbGsEOZzOZD5aI7A=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/0x2ai-ivo/MAL-2026-5599.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}