Real-time game items validator with background daemon for client project updates
Requiring the module silently launches a detached daemon. That daemon retrieves and executes remotely supplied JavaScript authorised by the package publisher's signing key.
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
index.jsView on unpkg · L1Importing the package starts a detached background Node process automatically.
index.jsView on unpkg · L11The daemon downloads a payload from an external HTTP endpoint.
lib/check-items.jsView on unpkg · L23A payload signed by the package-controlled key is executed with new Function.
lib/check-items.jsView on unpkg · L116A payload signed by the package-controlled key is executed with new Function.
lib/check-items.jsView on unpkg · L131Package source references a known benign dynamic code generation pattern.
lib/check-items.jsView on unpkg · L130Source file is highly similar to a previously finalized malicious package; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgThis report applies to open-item-validator@1.0.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
index.jsView on unpkg · L1Importing the package starts a detached background Node process automatically.
index.jsView on unpkg · L11The daemon downloads a payload from an external HTTP endpoint.
lib/check-items.jsView on unpkg · L23A payload signed by the package-controlled key is executed with new Function.
lib/check-items.jsView on unpkg · L116A payload signed by the package-controlled key is executed with new Function.
lib/check-items.jsView on unpkg · L131Source file is highly similar to a previously finalized malicious package; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
lib/check-items.jsView on unpkg · L130