MAL-2026-12032

    Dashboard / Malicious Package / MAL-2026-12032

    MAL-2026-12032

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in add-two-numbers-x7q9m (npm)

    Details: Source: amazon-inspector (550dfc48a74577d95e53fc64cc296a9cc59a5940edb6eac3f191f41376350635) The package advertises itself as a trivial 'add two numbers' utility but its preinstall lifecycle script enumerates the installer's Desktop directory, reads.txt files, applies a regex (/npm_[A-Za-z0-9_-]+/) to extract npm authentication tokens, and transmits any match as a query parameter to the hardcoded endpoint https://lively-bird-15.webhook.cool. This runs automatically on `npm install`. The behavior has no relation to the package's advertised arithmetic functionality, and the random name suffix is consistent with a disposable malicious-publish account. Harvested npm tokens enable registry account takeover and downstream supply-chain propagation via the victim's publish rights.

    Affected packages

    Package

    Name: add-two-numbers-x7q9m

    Purl: pkg:npm/add-two-numbers-x7q9m

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    1.0.1
    MAL-2026-12032 | CVE-DB