magika-js @4.1.1
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 12:52 PM UTC
OSV ID
MAL-2026-14247
Ecosystem
npm
Summary
magika-js is a typosquat of Google's magika library. The postinstall lifecycle script collects installer host identifiers (hostname, platform, arch, node version, package name, npm lifecycle event, timestamp) and POSTs them as JSON to the hardcoded endpoint https://ucjtw03t.instances.poc.jchunt.top/magika-js. The beacon fires automatically on npm install with no opt-in and no documented purpose served by the transmission, sending installer machine data to a non-publisher domain. A source.txt pointer to github.com/google/magika reinforces the impersonation of Google's project.
Source: amazon-inspector (41cd28e41bc842fd046a2bff254f450edd0b6d2d15d961fe768cf5e9ebfa197f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.