MAL-2026-17306

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-loader-core/MAL-2026-17306.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17306
Published
2026-09-30T01:25:34Z
Modified
2026-09-30T01:45:10Z
Summary
Malicious code in fabric-loader-core (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a11b2ce0f9b1a7b7587acd21c631a72069bab0216c8bf010f4fb04f8b0ae543f)

The package's postinstall hook runs index.js, which performs an HTTPS GET to the hardcoded host https://fabric-npm.gm-service.xyz/p and passes the response body directly to vm.runInContext with a context exposing require, process, Buffer, timers, and console. Whatever bytes that server returns execute at npm install time with full Node privileges on the installer's machine. The advertised purpose ("Native asset loader bridge for Fabric mod environments") does not match the code: lib/renderer.js is an inert stub with no-op exports, and index.js contains only the remote fetch-and-eval loader. The package name evokes the unrelated Fabric Minecraft mod ecosystem, which is a cover story. The remote host controls the payload and can change it at any time, so installer impact is unbounded and can include credential theft, persistence, or lateral movement.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020779",
            "import_time":  "2026-09-30T01:36:50.955619578Z",
            "modified_time":  "2026-09-30T01:25:34Z",
            "sha256":  "a11b2ce0f9b1a7b7587acd21c631a72069bab0216c8bf010f4fb04f8b0ae543f",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / fabric-loader-core

Package

Name
fabric-loader-core
View open source insights on deps.dev
Purl
pkg:npm/fabric-loader-core

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "615f67404e631a9c5c2f81442b2b99e615e19d3e7803e4436dfcd3e49f46fbc7",
            "tlsh":  "2ef0dd36bbed6125272054eca4838806c86be2232212f690f69c42586fca53cf1d6798"
        },
        {
            "path":  "package.json",
            "sha256":  "64b4532f14010e3f8afbb92102d3c3fcf1d1756618d958d9052938c60337febb",
            "tlsh":  "25e0cd206a20d62320d4d7705e36495536204f1b4044bc6d61a7115cd3ce77545fb35b"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "fabric-loader-core-1.0.0.tgz",
            "hashes":  {
                "sha1":  "3f5accb342b941a348c57b9b9912b5c94cc3fb05",
                "sha512_sri":  "sha512-IE/e13oz87A/GBxkHw/24iCRWeW4fnXQ41P8x1S462slG8//wZ5PRDpwpGit+RnkY6pPVNf6fkn/jQ2SUmafMw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-loader-core/MAL-2026-17306.json"