-= Per source details. Do not edit below this line.=-
package.json declares postinstall="node index.js", so npm install fabric-render-bridge automatically executes index.js. index.js reads Minecraft launcher credential stores across multiple launchers (launcher_accounts.json and launcher_profiles.json for the official launcher, PrismLauncher, MultiMC, TLauncher, Modrinth, PolyMC, GDLauncher) plus a session dump from the OS temp directory, extracts accessToken/refreshToken values and account usernames, and POSTs them via https.request to a hardcoded Discord webhook at discord.com/api/webhooks/1554065488726990909/. A separate sendInfo() routine POSTs os.hostname(), os.userInfo().username, os.platform() and os.release() to the same webhook on every install. The package presents itself as a Fabric render bridge but ships no rendering functionality; its sole install-time behavior is credential and host-identity theft.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020585",
"import_time": "2026-09-28T18:24:38.018536331Z",
"modified_time": "2026-09-28T18:02:39Z",
"sha256": "c2715ef0b07fbf0ca24fb8dadec44f2fcfdc273421a49ad2201bf8e40d3e2c01",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "11609527f87f8196eba27120de18a9a74cf1ba626d8611bb3d970bf62e785ae4",
"tlsh": "c3e1637985f214227667e66d3f0b550a226172433248cd7cba9cf3901fee42d92b36bd"
}
],
"package_integrity": [
{
"filename": "fabric-render-bridge-1.0.0.tgz",
"hashes": {
"sha1": "c129bd9334e52c70128b4af1f9a4e7b8d73f1a6e",
"sha512_sri": "sha512-cMCxWjXKagQO8UspeEB/isQfba/hIGuw8EqUzz0V6RfaAVVlVstNdruyFufJw9Qvjm8u4tVoJHLTJFwsgDt1PA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-render-bridge/MAL-2026-17225.json"