MAL-2026-17224

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-asset-pipeline/MAL-2026-17224.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17224
Published
2026-09-28T18:02:57Z
Modified
2026-09-28T18:30:06Z
Summary
Malicious code in fabric-asset-pipeline (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (bb92787d766d5bfa0c384cc04909689215fa0d3e869630422caa8bedd303038a)

fabric-asset-pipeline@1.0.0 declares a postinstall hook that runs index.js on npm install. index.js is heavily obfuscated (obfuscator.io-style rotated string array plus base64+RC4 decoding of identifiers and URLs, with newline/regex anti-formatting hooks) and implements a Minecraft credential stealer: functions stealLauncherAccounts(), stealAltLaunchers(), and readSessionDump() read account credential stores from the official Minecraft launcher (launcher_accounts.json / launcher_profiles.json) as well as Prism/MultiMC, TLauncher, Modrinth, PolyMC, and GDLauncher, plus a session dump from the OS temp directory. Extracted account names, access tokens, and refresh tokens are POSTed via https.request to a hardcoded webhook whose URL is RC4-decoded at runtime. A companion sendInfo() call ships os.hostname(), os.userInfo().username, os.platform()/os.release(), and the recovered Minecraft username to the same endpoint. None of this behavior is part of the package's advertised 'asset loader bridge' purpose, and the obfuscation deliberately conceals both the exfiltration functions and the destination URL.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020587",
            "import_time":  "2026-09-28T18:24:38.244113777Z",
            "modified_time":  "2026-09-28T18:02:57Z",
            "sha256":  "91f1a39d9b2973128a011604fd549db31ce81fc9929ff1a1066a21f89a2d1607",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.1"
            ]
        },
        {
            "id":  "IN-MAL-2026-020589",
            "import_time":  "2026-09-28T18:24:38.422326484Z",
            "modified_time":  "2026-09-28T18:03:18Z",
            "sha256":  "bb92787d766d5bfa0c384cc04909689215fa0d3e869630422caa8bedd303038a",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / fabric-asset-pipeline

Package

Name
fabric-asset-pipeline
View open source insights on deps.dev
Purl
pkg:npm/fabric-asset-pipeline

Affected ranges

Affected versions

1.*
1.0.0
1.0.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "fbb0310ad9c6e1dd51a33c4cd6a308819ca079a3a3cefcee443e587104df23b2",
            "tlsh":  "71b1b65695e25566023bf2b81e1b926a7276b7133249cc7c75acd2d40f2e43c17b328c"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "fabric-asset-pipeline-1.0.1.tgz",
            "hashes":  {
                "sha1":  "9bc409dcc449c98f4a36ae1e868b006b3e357410",
                "sha512_sri":  "sha512-3q/ciCtT/sfaevELPe4itz6an9zjFUCM9NGRvM4LwHwiLAxG9wiq83sYCz9XKdSIfaxmyF0veBRssrTrolfu6w=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-asset-pipeline/MAL-2026-17224.json"