box-sign-client-poc@1.0.0
Vulnerability report · Last retrieved from osv.dev September 4, 2026 at 3:57 PM UTC
OSV ID
MAL-2026-15921
Ecosystem
npm
Summary
package.json declares a preinstall hook that runs index.js on npm install. The script reads the installer's hostname and OS username, embeds them together with a timestamp into a DNS subdomain of the form poc-<hostname>-<user>-<timestamp>.iv6mfybhp42k33ysmzi73de5w.canarytokens.com, and issues a DNS resolution for that name, causing the installer's host and user identifiers to be transmitted to a third-party canarytokens.com collector at install time. The package name and framing indicate a dependency-confusion proof-of-concept targeting a Box-branded internal package, but the exfiltration primitive runs against any machine that installs it.
Source: amazon-inspector (cc47a8e8a147ec412ecc05d666655b675a36b9eec0823e278767a286993e7e0d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.