open-item-validator@1.0.2
Malicious code in open-item-validator (npm)
Analysis
On require, this package silently spawns a detached background daemon (node lib/check-items.js) that fetches a code payload over plain HTTP from hxxp://itemx[.]servegame[.]com:8888/api/x-realtime and executes it via new Function('require','module', code) after verifying an RSA-SHA256 signature against a bundled public key. The signature only authenticates the publisher's own server, so the publisher retains arbitrary remote code execution on every machine that requires the package. The daemon runs automatically on require with no opt-in, and the fetched code is obfuscated (dictionary-array / _0x-style).
- analyzed by
- Leitwacht
- first seen
- Sep 7, 2026, 07:35 PM
- analyzed
- Sep 7, 2026, 07:36 PM
Related advisories
- date-fns-formatter@1.3.8
- multicore-kit@1.1.5
- jwt-logger@2.1.9
- ulid-intel@2.12.3
- 2nestjs@0.0.1
- 1nestjs@0.0.1
- 0nestjs@0.0.1
- hydration-ui-pkg@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.