OpenSSF/OSV advisory MAL-2026-14247 confirms this npm version as malicious. magika-js is a typosquat of Google's magika library. The postinstall lifecycle script collects installer host identifiers (hostname, platform, arch, node version, package name, npm lifecycle event, timestamp) and POSTs them as JSON to the hardcoded endpoint https://ucjtw03t.instances.poc.jchunt.top/magika-js...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource appears to send environment or credential material to an external endpoint.
postinstall.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
postinstall.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
postinstall.jsView on unpkg · L2Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource appears to send environment or credential material to an external endpoint.
postinstall.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
postinstall.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
postinstall.jsView on unpkg · L2