VDB
KO

MAL-2026-12032

Malicious code in add-two-numbers-x7q9m (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (550dfc48a74577d95e53fc64cc296a9cc59a5940edb6eac3f191f41376350635) The package advertises itself as a trivial 'add two numbers' utility but its preinstall lifecycle script enumerates the installer's Desktop directory, reads.txt files, applies a regex (/npm_[A-Za-z0-9_-]+/) to extract npm authentication tokens, and transmits any match as a query parameter to the hardcoded endpoint https://lively-bird-15.webhook.cool. This runs automatically on `npm install`. The behavior has no relation to the package's advertised arithmetic functionality, and the random name suffix is consistent with a disposable malicious-publish account. Harvested npm tokens enable registry account takeover and downstream supply-chain propagation via the victim's publish rights.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / add-two-numbers-x7q9m

No fixed version published yet for add-two-numbers-x7q9m (npm). Pin to a known-safe version or switch to an alternative.

References