Real-time game items validator with background daemon for client project updates
Importing the module creates a detached daemon that downloads and executes code selected by the package operator. A signature gate does not constrain what the signing server may run.
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
index.jsView on unpkg · L1Importing the package automatically starts a detached background Node process.
index.jsView on unpkg · L13The daemon fetches JavaScript from a hard-coded remote endpoint.
lib/check-items.jsView on unpkg · L30The fetched server-controlled code is executed with Node's require capability through Function.
lib/check-items.jsView on unpkg · L136Package source references a known benign dynamic code generation pattern.
lib/check-items.jsView on unpkg · L136Source file is highly similar to a previously finalized malicious package; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgPackage documentation addresses scanner classification and asserts that signed code has no malware risk.
SECURITY_SETUP.mdView on unpkg · L157This report applies to open-item-validator@1.0.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
index.jsView on unpkg · L1Importing the package automatically starts a detached background Node process.
index.jsView on unpkg · L13The daemon fetches JavaScript from a hard-coded remote endpoint.
lib/check-items.jsView on unpkg · L30The fetched server-controlled code is executed with Node's require capability through Function.
lib/check-items.jsView on unpkg · L136Package source references a known benign dynamic code generation pattern.
lib/check-items.jsView on unpkg · L136Source file is highly similar to a previously finalized malicious package; route for source-aware review.
SERVER_IMPLEMENTATION_EXAMPLE.jsView on unpkgPackage documentation addresses scanner classification and asserts that signed code has no malware risk.
SECURITY_SETUP.mdView on unpkg · L157