Real-time game items validator with background daemon for client project updates
Importing the package creates a detached daemon. The daemon downloads and executes arbitrary code authorized by the remote signing key.
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
index.jsView on unpkg · L1Importing the main module silently starts a detached background Node process.
index.jsView on unpkg · L8The daemon fetches a payload over unencrypted HTTP from a package-controlled endpoint.
lib/check-items.jsView on unpkg · L28A server-signed response body is executed with Node's require capability through dynamic code generation.
lib/check-items.jsView on unpkg · L116Source file is highly similar to a previously finalized malicious package; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgThis report applies to open-item-validator@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A server-signed response body is executed with Node's require capability through dynamic code generation.
Package source references a known benign dynamic code generation pattern.
lib/check-items.jsView on unpkg · L130Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
index.jsView on unpkg · L1Importing the main module silently starts a detached background Node process.
index.jsView on unpkg · L8The daemon fetches a payload over unencrypted HTTP from a package-controlled endpoint.
lib/check-items.jsView on unpkg · L28A server-signed response body is executed with Node's require capability through dynamic code generation.
lib/check-items.jsView on unpkg · L116Source file is highly similar to a previously finalized malicious package; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgA server-signed response body is executed with Node's require capability through dynamic code generation.
Package source references a known benign dynamic code generation pattern.
lib/check-items.jsView on unpkg · L130