{"id":"MAL-2026-17225","summary":"Malicious code in fabric-render-bridge (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c2715ef0b07fbf0ca24fb8dadec44f2fcfdc273421a49ad2201bf8e40d3e2c01)\npackage.json declares postinstall=\"node index.js\", so `npm install fabric-render-bridge` automatically executes index.js. index.js reads Minecraft launcher credential stores across multiple launchers (launcher_accounts.json and launcher_profiles.json for the official launcher, PrismLauncher, MultiMC, TLauncher, Modrinth, PolyMC, GDLauncher) plus a session dump from the OS temp directory, extracts accessToken/refreshToken values and account usernames, and POSTs them via https.request to a hardcoded Discord webhook at discord.com/api/webhooks/1554065488726990909/. A separate sendInfo() routine POSTs os.hostname(), os.userInfo().username, os.platform() and os.release() to the same webhook on every install. The package presents itself as a Fabric render bridge but ships no rendering functionality; its sole install-time behavior is credential and host-identity theft.\n","modified":"2026-09-28T18:30:05.543130018Z","published":"2026-09-28T18:02:39Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020585","import_time":"2026-09-28T18:24:38.018536331Z","modified_time":"2026-09-28T18:02:39Z","sha256":"c2715ef0b07fbf0ca24fb8dadec44f2fcfdc273421a49ad2201bf8e40d3e2c01","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/fabric-render-bridge/v/1.0.0"}],"affected":[{"package":{"name":"fabric-render-bridge","ecosystem":"npm","purl":"pkg:npm/fabric-render-bridge"},"versions":["1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"11609527f87f8196eba27120de18a9a74cf1ba626d8611bb3d970bf62e785ae4","tlsh":"c3e1637985f214227667e66d3f0b550a226172433248cd7cba9cf3901fee42d92b36bd"}],"package_integrity":[{"hashes":{"sha1":"c129bd9334e52c70128b4af1f9a4e7b8d73f1a6e","sha512_sri":"sha512-cMCxWjXKagQO8UspeEB/isQfba/hIGuw8EqUzz0V6RfaAVVlVstNdruyFufJw9Qvjm8u4tVoJHLTJFwsgDt1PA=="},"filename":"fabric-render-bridge-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-render-bridge/MAL-2026-17225.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}