MAL-2026-14247

    Dashboard / Malicious Package / MAL-2026-14247

    MAL-2026-14247

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in magika-js (npm)

    Details: Source: amazon-inspector (41cd28e41bc842fd046a2bff254f450edd0b6d2d15d961fe768cf5e9ebfa197f) magika-js is a typosquat of Google's magika library. The postinstall lifecycle script collects installer host identifiers (hostname, platform, arch, node version, package name, npm lifecycle event, timestamp) and POSTs them as JSON to the hardcoded endpoint https://ucjtw03t.instances.poc.jchunt.top/magika-js. The beacon fires automatically on npm install with no opt-in and no documented purpose served by the transmission, sending installer machine data to a non-publisher domain. A source.txt pointer to github.com/google/magika reinforces the impersonation of Google's project.

    Affected packages

    Package

    Name: magika-js

    Purl: pkg:npm/magika-js

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    4.1.1
    MAL-2026-14247 | CVE-DB