-= Per source details. Do not edit below this line.=-
On require(), index.js spawns a detached, unref'd background Node process (lib/check-items.js) that repeatedly HTTP-GETs a JSON payload from http://itemx.servegame.com:8888/api/x-realtime and executes the returned JavaScript via new Function('require','module', payload.code)(require, moduleObj). The daemon survives the parent process and re-polls the endpoint on a configured interval, so whoever controls that endpoint runs arbitrary Node code on the installer's host on library load and continuously thereafter. The fetch is over plain HTTP to a No-IP dynamic-DNS host (servegame.com) that does not match the publisher's declared homepage (game.spawnrealm.com); a bundled RSA signature check does not alter that the endpoint operator chooses what code runs. README framing as 'signed game code updates' is inconsistent with the shipped generic fetch-and-exec mechanism and the publisher/destination host mismatch.
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-019720",
"import_time": "2026-09-08T22:15:50.407159479Z",
"modified_time": "2026-09-08T21:56:18Z",
"sha256": "7ba5b55d57f4938bf2494d369d14434bb80ba6f6c712c7f8d89ae773c27dc457",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
},
{
"id": "IN-MAL-2026-019719",
"import_time": "2026-09-08T22:15:50.366549708Z",
"modified_time": "2026-09-08T21:56:09Z",
"sha256": "ee1ac3d27c505e6a6e95a5544939630fdb29b701cbe41f095d7431cd4a2c83aa",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
},
{
"id": "IN-MAL-2026-019851",
"import_time": "2026-09-09T07:20:44.067356297Z",
"modified_time": "2026-09-09T06:58:04Z",
"sha256": "5969fb446f5d7799038ef9ba9fe8affe2a52fa4a4ead78972468dfbee8e5fb37",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
},
{
"id": "IN-MAL-2026-019853",
"import_time": "2026-09-09T07:20:44.254346612Z",
"modified_time": "2026-09-09T06:58:24Z",
"sha256": "644e4428fb51fc8b74e205a3115a7765fe004741a307179b71c91060b1bdbe2f",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-019854",
"import_time": "2026-09-09T07:20:44.367114832Z",
"modified_time": "2026-09-09T06:58:34Z",
"sha256": "6dd0888ad306ae546ce2b0d6a482de9139a165174d14ff4afeee199b87b77c5d",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
},
{
"id": "IN-MAL-2026-019852",
"import_time": "2026-09-09T07:20:44.1602428Z",
"modified_time": "2026-09-09T06:58:15Z",
"sha256": "fa5f923c619fb110019899ac88d32bfe2bd195fbffdcde853b618ae5be3f360e",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "GHSA-55qh-42r8-hcgq",
"import_time": "2026-09-28T06:54:42.876865184Z",
"modified_time": "2026-09-28T05:54:48Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "5734c86f1289f980635bd730b9fe0a87dc2def30694a0beedf1fb84ab7303b66",
"source": "ghsa-malware"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "lib/check-items.js",
"sha256": "4b73aed06386ca7d176db5e8da14cdcf33a78e9d25b2d5ae31a6206133a246a0",
"tlsh": "3491734ead4b92371eb742f44317502afb5e91932691d205bbcdd34c2fb8118e325cea"
},
{
"path": "index.js",
"sha256": "0f036bd6bbfba26d056465135e91d99bd428210fdc42473ab463bae06e21a32e",
"tlsh": "d11121ea32caa52a7c32afe1e9338111be16c11277004001b9edbad60fe19864353cbd"
}
],
"package_integrity": [
{
"filename": "open-item-validator-1.0.3.tgz",
"hashes": {
"sha1": "e267496a8e5871b9b287b0646d1c0419ab98230b",
"sha512_sri": "sha512-iHtWqOLOZCP2tMXCKpKbeyZumJ0FoSEjwqLFnKULXIK9ja8IfhO4c1g6hivmHBfggM8ejgGZcfaOXW2Na5HGIQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/open-item-validator/MAL-2026-16052.json"