Malicious code in box-react-uix (npm)
The box-react-uix npm package is a malicious package published as part of a dependency confusion campaign. It uses a preinstall script to execute code during npm install that collects and sends the installer's public IP address and host telemetry, including personally identifiable information, to an attacker-controlled Sentry endpoint. The package name mimics an internal namespace to trick misconfigured resolvers into installing it instead of legitimate private dependencies. The payload is consistent across all packages published by the attacker, differing only in package name and Sentry project ID. This behavior is reconnaissance-focused, allowing attribution of installs to specific victim organizations. The package version 18.6.91 is affected. There is no official patch or fix available. Installing or running this package may fully compromise the host, and all secrets on the host should be rotated from a different machine.
AI Analysis
Technical Summary
The box-react-uix package published on npm by user 'click2ai' is a malicious package designed for dependency confusion attacks. It declares a preinstall hook that runs automatically during npm install, which installs @sentry/node and executes a script that initializes a Sentry client with a hardcoded attacker-controlled DSN. This script collects the installer's public IP address via Cloudflare's trace endpoint, attaches default PII such as hostname and OS username, and sends this telemetry to the attacker's Sentry project. The package name mimics an internal 'box' namespace to trick misconfigured resolvers into installing it instead of legitimate private packages. The payload is identical across all packages from this attacker, differing only in the targeted Sentry project ID, enabling attribution of installs to specific victims. The runtime initialization also defaults to the attacker’s Sentry endpoint if no DSN is provided, silently exfiltrating errors and PII. The package contains no legitimate UI code, consistent with a lure and reconnaissance tactic. The affected version is 18.6.91. There is no evidence of known exploits in the wild, but any system with this package installed should be considered fully compromised.
Potential Impact
Installing the box-react-uix package version 18.6.91 results in automatic execution of a preinstall script that collects and exfiltrates the host's public IP address and personally identifiable information (PII) such as hostname and OS username to an attacker-controlled Sentry endpoint. This compromises the confidentiality of the host environment and enables the attacker to identify and attribute installations to specific organizations. The runtime code also silently sends errors and PII to the attacker if the consumer does not provide their own Sentry DSN, increasing the risk of ongoing data leakage. According to the ghsa-malware source, any computer with this package installed or running should be considered fully compromised, requiring immediate secret and key rotation from a different machine. Removal of the package alone does not guarantee full remediation due to potential further compromise.
Mitigation Recommendations
There is no official patch or fix available for this malicious package. The best mitigation is to avoid installing the box-react-uix package and audit your dependency configurations to prevent dependency confusion attacks by ensuring private packages are resolved correctly. If this package has been installed, remove it immediately and consider the host fully compromised. Rotate all secrets and keys stored on the affected host from a separate, trusted machine. Monitor for any signs of further compromise and rebuild affected systems if necessary. Review and tighten npm resolver configurations to prevent installation of similarly named malicious packages.
Malicious code in box-react-uix (npm)
Description
The box-react-uix npm package is a malicious package published as part of a dependency confusion campaign. It uses a preinstall script to execute code during npm install that collects and sends the installer's public IP address and host telemetry, including personally identifiable information, to an attacker-controlled Sentry endpoint. The package name mimics an internal namespace to trick misconfigured resolvers into installing it instead of legitimate private dependencies. The payload is consistent across all packages published by the attacker, differing only in package name and Sentry project ID. This behavior is reconnaissance-focused, allowing attribution of installs to specific victim organizations. The package version 18.6.91 is affected. There is no official patch or fix available. Installing or running this package may fully compromise the host, and all secrets on the host should be rotated from a different machine.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The box-react-uix package published on npm by user 'click2ai' is a malicious package designed for dependency confusion attacks. It declares a preinstall hook that runs automatically during npm install, which installs @sentry/node and executes a script that initializes a Sentry client with a hardcoded attacker-controlled DSN. This script collects the installer's public IP address via Cloudflare's trace endpoint, attaches default PII such as hostname and OS username, and sends this telemetry to the attacker's Sentry project. The package name mimics an internal 'box' namespace to trick misconfigured resolvers into installing it instead of legitimate private packages. The payload is identical across all packages from this attacker, differing only in the targeted Sentry project ID, enabling attribution of installs to specific victims. The runtime initialization also defaults to the attacker’s Sentry endpoint if no DSN is provided, silently exfiltrating errors and PII. The package contains no legitimate UI code, consistent with a lure and reconnaissance tactic. The affected version is 18.6.91. There is no evidence of known exploits in the wild, but any system with this package installed should be considered fully compromised.
Potential Impact
Installing the box-react-uix package version 18.6.91 results in automatic execution of a preinstall script that collects and exfiltrates the host's public IP address and personally identifiable information (PII) such as hostname and OS username to an attacker-controlled Sentry endpoint. This compromises the confidentiality of the host environment and enables the attacker to identify and attribute installations to specific organizations. The runtime code also silently sends errors and PII to the attacker if the consumer does not provide their own Sentry DSN, increasing the risk of ongoing data leakage. According to the ghsa-malware source, any computer with this package installed or running should be considered fully compromised, requiring immediate secret and key rotation from a different machine. Removal of the package alone does not guarantee full remediation due to potential further compromise.
Mitigation Recommendations
There is no official patch or fix available for this malicious package. The best mitigation is to avoid installing the box-react-uix package and audit your dependency configurations to prevent dependency confusion attacks by ensuring private packages are resolved correctly. If this package has been installed, remove it immediately and consider the host fully compromised. Rotate all secrets and keys stored on the affected host from a separate, trusted machine. Monitor for any signs of further compromise and rebuild affected systems if necessary. Review and tighten npm resolver configurations to prevent installation of similarly named malicious packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10227
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-f4fv-qwcg-667v"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ff7768715ace432f260e
Added to database: 07/14/2026, 09:20:55 UTC
Last enriched: 07/14/2026, 09:38:33 UTC
Last updated: 07/24/2026, 21:47:34 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.