MAL-2026-17232

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-native-loader/MAL-2026-17232.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17232
Published
2026-09-28T22:04:12Z
Modified
2026-09-28T22:30:05Z
Summary
Malicious code in fabric-native-loader (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (d289ae71736f05158f45d6636730641e82b5a774bf99bf1b587155d31c73daaa)

package.json declares a postinstall hook that runs index.js on npm install. index.js reads Minecraft launcher credential stores (launcher_accounts.json, launcher_profiles.json, and equivalent files for Prism, MultiMC, TLauncher, Modrinth, PolyMC, GDLauncher), extracting Mojang/Microsoft accessTokens, refreshTokens, and clientTokens. It also recursively walks the.minecraft directory reading.json/.txt/.cfg/.properties/.yml/.log files and matches their contents against JWT and Bearer-token regexes. The collected credentials are combined with os.hostname(), os.userInfo().username, and os.platform() and POSTed via HTTPS to a hardcoded Discord webhook (discord.com/api/webhooks/1554065488726990909/...). No functionality matching the package name is present; the sole effect of installing the package is credential theft against the installer.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020613",
            "import_time":  "2026-09-28T22:18:22.731432822Z",
            "modified_time":  "2026-09-28T22:04:12Z",
            "sha256":  "d289ae71736f05158f45d6636730641e82b5a774bf99bf1b587155d31c73daaa",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / fabric-native-loader

Package

Name
fabric-native-loader
View open source insights on deps.dev
Purl
pkg:npm/fabric-native-loader

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "d10b03a38f8bddea0dceb4ee1ab4d9baa4b3e0a1e9ed08d7e9821dec1b4df338",
            "tlsh":  "e6c1849e56f36522427bb6d5274f051631a56a0b3146cc0c3b5cc3d82f4e02d92f35ae"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "fabric-native-loader-1.0.0.tgz",
            "hashes":  {
                "sha1":  "2a94151dd544dc022f74563c19e7eeccc0081af1",
                "sha512_sri":  "sha512-u4a1UHRdSmLMOi/QXgLJkopIbE/btoeXEUDzkJuDWcXGU+DeZAWngTZw6cDKZk2TPxs/3iUB7aJcM1+uxItYsg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-native-loader/MAL-2026-17232.json"