LWA-2026-11932 MAL-2026-16052 ↗ confirmed malware

open-item-validator@1.0.2

Malicious code in open-item-validator (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

On require, this package silently spawns a detached background daemon (node lib/check-items.js) that fetches a code payload over plain HTTP from hxxp://itemx[.]servegame[.]com:8888/api/x-realtime and executes it via new Function('require','module', code) after verifying an RSA-SHA256 signature against a bundled public key. The signature only authenticates the publisher's own server, so the publisher retains arbitrary remote code execution on every machine that requires the package. The daemon runs automatically on require with no opt-in, and the fetched code is obfuscated (dictionary-array / _0x-style).

analyzed by
Leitwacht
first seen
Sep 7, 2026, 07:35 PM
analyzed
Sep 7, 2026, 07:36 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.