MAL-2026-15921
Dashboard / Malicious Package / MAL-2026-15921
MAL-2026-15921
Summary: Malicious code in box-sign-client-poc (npm)
Details: Source: amazon-inspector (cc47a8e8a147ec412ecc05d666655b675a36b9eec0823e278767a286993e7e0d) package.json declares a preinstall hook that runs index.js on `npm install`. The script reads the installer's hostname and OS username, embeds them together with a timestamp into a DNS subdomain of the form `poc-<hostname>-<user>-<timestamp>.iv6mfybhp42k33ysmzi73de5w.canarytokens.com`, and issues a DNS resolution for that name, causing the installer's host and user identifiers to be transmitted to a third-party canarytokens.com collector at install time. The package name and framing indicate a dependency-confusion proof-of-concept targeting a Box-branded internal package, but the exfiltration primitive runs against any machine that installs it.
Affected packages
Package
Name: box-sign-client-poc
Purl: pkg:npm/box-sign-client-poc
Affected ranges
Type: N/A
Events:
