MAL-2026-12032
Malicious code in add-two-numbers-x7q9m (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (550dfc48a74577d95e53fc64cc296a9cc59a5940edb6eac3f191f41376350635) The package advertises itself as a trivial 'add two numbers' utility but its preinstall lifecycle script enumerates the installer's Desktop directory, reads.txt files, applies a regex (/npm_[A-Za-z0-9_-]+/) to extract npm authentication tokens, and transmits any match as a query parameter to the hardcoded endpoint https://lively-bird-15.webhook.cool. This runs automatically on `npm install`. The behavior has no relation to the package's advertised arithmetic functionality, and the random name suffix is consistent with a disposable malicious-publish account. Harvested npm tokens enable registry account takeover and downstream supply-chain propagation via the victim's publish rights.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for add-two-numbers-x7q9m (npm). Pin to a known-safe version or switch to an alternative.