MAL-2026-15921

    Dashboard / Malicious Package / MAL-2026-15921

    MAL-2026-15921

    Published: 4 Sept 2026Last Modified: 4 Sept 2026

    Summary: Malicious code in box-sign-client-poc (npm)

    Details: Source: amazon-inspector (cc47a8e8a147ec412ecc05d666655b675a36b9eec0823e278767a286993e7e0d) package.json declares a preinstall hook that runs index.js on `npm install`. The script reads the installer's hostname and OS username, embeds them together with a timestamp into a DNS subdomain of the form `poc-<hostname>-<user>-<timestamp>.iv6mfybhp42k33ysmzi73de5w.canarytokens.com`, and issues a DNS resolution for that name, causing the installer's host and user identifiers to be transmitted to a third-party canarytokens.com collector at install time. The package name and framing indicate a dependency-confusion proof-of-concept targeting a Box-branded internal package, but the exfiltration primitive runs against any machine that installs it.

    Affected packages

    Package

    Name: box-sign-client-poc

    Purl: pkg:npm/box-sign-client-poc

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0