@magda/semantic-indexer-sdk @7.0.0-pr.3637.5
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2025-47009
Ecosystem
npm
Summary
@magda/semantic-indexer-sdk ships a minified bundle (dist/index.js) that contains multiple HTTP POST call sites and a literal 'dyndns' substring. These are keyword co-occurrences typical of a bundled SDK: HTTP client code performing configurable POST requests against caller/config-supplied endpoints, and a 'dyndns' token likely originating from an embedded library or documentation string rather than a hardcoded C2 destination. No specific installer-side secret is read and exfiltrated to a hardcoded attacker-controlled host, no lifecycle scripts fetch or execute remote code, no credential-store or wallet/browser enumeration path is present, and no import/require-time side effect posts installer data off-host. The package presents as an SDK for the Magda data catalog project consistent with its scope.
Source: amazon-inspector (57e758f2e76254912dbf57ec99d3ed2da95ed1725239ce03d03392d903ee7078)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.