{"id":"MAL-2026-15920","summary":"Malicious code in box-sign-client (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (76143eab11057809af00414cb665446366f039e3cbf1fa82aae06a1093cbbf49)\nbox-sign-client@1.0.0 is a dependency-confusion vehicle positioned against the internal Box namespace (@box/sign-client). Its package.json declares a preinstall script (`node index.js`) that reads `os.hostname()` and `process.env.USER`/`USERNAME`, embeds those values into a subdomain of the hardcoded host `iv6mfybhp42k33ysmzi73de5w.canarytokens.com`, and calls `dns.resolve()` to trigger a DNS lookup against that subdomain. On any `npm install` that resolves this public package instead of the intended internal one, the installing host's hostname and login user are transmitted via DNS to a third-party Canarytokens collector at install time, before any application code is run. The package advertises itself as a proof-of-concept for Box dependency confusion, but the beacon fires against any installer regardless of intent.\n","modified":"2026-09-04T07:00:09.429768730Z","published":"2026-09-04T06:38:17Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-04T06:53:31.726239799Z","modified_time":"2026-09-04T06:38:17Z","sha256":"76143eab11057809af00414cb665446366f039e3cbf1fa82aae06a1093cbbf49","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-019638"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/box-sign-client/v/1.0.0"}],"affected":[{"package":{"name":"box-sign-client","ecosystem":"npm","purl":"pkg:npm/box-sign-client"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/box-sign-client/MAL-2026-15920.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"8eaf5131b39e711e6f015ecf8012ee452011ba0094795496e5101e2dd8f7873b","tlsh":"4751ab9469fc40383577488a9497653ba86cefa23346fd20766c424a4ec3bb9d7131bf"},{"sha256":"8dac85eaeeb2a3e7bec10e3b8ad717fd8a49a83b4975437fb8c07c2d86259ecc","tlsh":"5ad022300c30e07324d01be189bb908346f20c2f0008bc08a3c7202885ce3ab06fe30e","path":"package.json"}],"package_integrity":[{"filename":"box-sign-client-1.0.0.tgz","hashes":{"sha1":"33c249f0358cb58bff8a42627e43d15740f34f57","sha512_sri":"sha512-omgoztQEW8CsF0S0OUz+RF6rKjn/gfb3ON7O1Ibq5UBNZPnEghOWViePI2ZO5OtnsQl1x4V6sn+RmIzZqe6URw=="}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}