Real-time game items validator with background daemon for client project updates
The package creates a background daemon merely when imported. That daemon downloads operator-controlled signed code and executes it.
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
index.jsView on unpkg · L1Importing the package automatically starts a detached Node daemon.
index.jsView on unpkg · L24Importing the package automatically starts a detached Node daemon.
index.jsView on unpkg · L13Package source references a known benign dynamic code generation pattern.
lib/check-items.jsView on unpkg · L136Source file is highly similar to a previously finalized malicious package; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgPackage metadata exposes index.js as the import entrypoint.
package.jsonView on unpkg · L5This report applies to items-validator@1.0.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
index.jsView on unpkg · L1Importing the package automatically starts a detached Node daemon.
index.jsView on unpkg · L13Importing the package automatically starts a detached Node daemon.
index.jsView on unpkg · L24Source file is highly similar to a previously finalized malicious package; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
lib/check-items.jsView on unpkg · L136Package metadata exposes index.js as the import entrypoint.
package.jsonView on unpkg · L5