-= Per source details. Do not edit below this line.=-
package.json declares a postinstall hook that runs index.js on npm install. index.js reads Minecraft launcher credential stores (launcher_accounts.json, launcher_profiles.json, and equivalent files for Prism, MultiMC, TLauncher, Modrinth, PolyMC, GDLauncher), extracting Mojang/Microsoft accessTokens, refreshTokens, and clientTokens. It also recursively walks the.minecraft directory reading.json/.txt/.cfg/.properties/.yml/.log files and matches their contents against JWT and Bearer-token regexes. The collected credentials are combined with os.hostname(), os.userInfo().username, and os.platform() and POSTed via HTTPS to a hardcoded Discord webhook (discord.com/api/webhooks/1554065488726990909/...). No functionality matching the package name is present; the sole effect of installing the package is credential theft against the installer.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020613",
"import_time": "2026-09-28T22:18:22.731432822Z",
"modified_time": "2026-09-28T22:04:12Z",
"sha256": "d289ae71736f05158f45d6636730641e82b5a774bf99bf1b587155d31c73daaa",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "d10b03a38f8bddea0dceb4ee1ab4d9baa4b3e0a1e9ed08d7e9821dec1b4df338",
"tlsh": "e6c1849e56f36522427bb6d5274f051631a56a0b3146cc0c3b5cc3d82f4e02d92f35ae"
}
],
"package_integrity": [
{
"filename": "fabric-native-loader-1.0.0.tgz",
"hashes": {
"sha1": "2a94151dd544dc022f74563c19e7eeccc0081af1",
"sha512_sri": "sha512-u4a1UHRdSmLMOi/QXgLJkopIbE/btoeXEUDzkJuDWcXGU+DeZAWngTZw6cDKZk2TPxs/3iUB7aJcM1+uxItYsg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-native-loader/MAL-2026-17232.json"