Real-time game items validator with background daemon for client project updates
Requiring the package starts a detached daemon that downloads and runs code controlled by its remote signing authority. This is remote code execution outside the published package contents.
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
index.jsView on unpkg · L1Importing the declared entry point silently starts a detached Node daemon.
index.jsView on unpkg · L8The daemon fetches code from a hard-coded remote host over HTTP.
lib/check-items.jsView on unpkg · L28After signature verification, the daemon executes the server-provided code with Node's require capability.
lib/check-items.jsView on unpkg · L116Package source references a known benign dynamic code generation pattern.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgSecurity setup text falsely claims a postinstall flow and says the scanner sees verification logic, which is reviewer manipulation.
SECURITY_SETUP.mdView on unpkg · L75This report applies to open-item-validator@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
index.jsView on unpkg · L1Importing the declared entry point silently starts a detached Node daemon.
index.jsView on unpkg · L8The daemon fetches code from a hard-coded remote host over HTTP.
lib/check-items.jsView on unpkg · L28After signature verification, the daemon executes the server-provided code with Node's require capability.
lib/check-items.jsView on unpkg · L116Package source references a known benign dynamic code generation pattern.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgSecurity setup text falsely claims a postinstall flow and says the scanner sees verification logic, which is reviewer manipulation.
SECURITY_SETUP.mdView on unpkg · L75