npm

magika-js @4.1.1

Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 12:52 PM UTC

Malicious

OSV ID

MAL-2026-14247

Ecosystem

npm

Summary

magika-js is a typosquat of Google's magika library. The postinstall lifecycle script collects installer host identifiers (hostname, platform, arch, node version, package name, npm lifecycle event, timestamp) and POSTs them as JSON to the hardcoded endpoint https://ucjtw03t.instances.poc.jchunt.top/magika-js. The beacon fires automatically on npm install with no opt-in and no documented purpose served by the transmission, sending installer machine data to a non-publisher domain. A source.txt pointer to github.com/google/magika reinforces the impersonation of Google's project.

Source: amazon-inspector (41cd28e41bc842fd046a2bff254f450edd0b6d2d15d961fe768cf5e9ebfa197f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.