MAL-2026-17225

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-render-bridge/MAL-2026-17225.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17225
Published
2026-09-28T18:02:39Z
Modified
2026-09-28T18:30:05Z
Summary
Malicious code in fabric-render-bridge (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (c2715ef0b07fbf0ca24fb8dadec44f2fcfdc273421a49ad2201bf8e40d3e2c01)

package.json declares postinstall="node index.js", so npm install fabric-render-bridge automatically executes index.js. index.js reads Minecraft launcher credential stores across multiple launchers (launcher_accounts.json and launcher_profiles.json for the official launcher, PrismLauncher, MultiMC, TLauncher, Modrinth, PolyMC, GDLauncher) plus a session dump from the OS temp directory, extracts accessToken/refreshToken values and account usernames, and POSTs them via https.request to a hardcoded Discord webhook at discord.com/api/webhooks/1554065488726990909/. A separate sendInfo() routine POSTs os.hostname(), os.userInfo().username, os.platform() and os.release() to the same webhook on every install. The package presents itself as a Fabric render bridge but ships no rendering functionality; its sole install-time behavior is credential and host-identity theft.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020585",
            "import_time":  "2026-09-28T18:24:38.018536331Z",
            "modified_time":  "2026-09-28T18:02:39Z",
            "sha256":  "c2715ef0b07fbf0ca24fb8dadec44f2fcfdc273421a49ad2201bf8e40d3e2c01",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / fabric-render-bridge

Package

Name
fabric-render-bridge
View open source insights on deps.dev
Purl
pkg:npm/fabric-render-bridge

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "11609527f87f8196eba27120de18a9a74cf1ba626d8611bb3d970bf62e785ae4",
            "tlsh":  "c3e1637985f214227667e66d3f0b550a226172433248cd7cba9cf3901fee42d92b36bd"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "fabric-render-bridge-1.0.0.tgz",
            "hashes":  {
                "sha1":  "c129bd9334e52c70128b4af1f9a4e7b8d73f1a6e",
                "sha512_sri":  "sha512-cMCxWjXKagQO8UspeEB/isQfba/hIGuw8EqUzz0V6RfaAVVlVstNdruyFufJw9Qvjm8u4tVoJHLTJFwsgDt1PA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-render-bridge/MAL-2026-17225.json"