{"id":"MAL-2026-17232","summary":"Malicious code in fabric-native-loader (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d289ae71736f05158f45d6636730641e82b5a774bf99bf1b587155d31c73daaa)\npackage.json declares a postinstall hook that runs index.js on npm install. index.js reads Minecraft launcher credential stores (launcher_accounts.json, launcher_profiles.json, and equivalent files for Prism, MultiMC, TLauncher, Modrinth, PolyMC, GDLauncher), extracting Mojang/Microsoft accessTokens, refreshTokens, and clientTokens. It also recursively walks the.minecraft directory reading.json/.txt/.cfg/.properties/.yml/.log files and matches their contents against JWT and Bearer-token regexes. The collected credentials are combined with os.hostname(), os.userInfo().username, and os.platform() and POSTed via HTTPS to a hardcoded Discord webhook (discord.com/api/webhooks/1554065488726990909/...). No functionality matching the package name is present; the sole effect of installing the package is credential theft against the installer.\n","modified":"2026-09-28T22:30:05.539050977Z","published":"2026-09-28T22:04:12Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-28T22:04:12Z","sha256":"d289ae71736f05158f45d6636730641e82b5a774bf99bf1b587155d31c73daaa","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020613","import_time":"2026-09-28T22:18:22.731432822Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/fabric-native-loader/v/1.0.0"}],"affected":[{"package":{"name":"fabric-native-loader","ecosystem":"npm","purl":"pkg:npm/fabric-native-loader"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"e6c1849e56f36522427bb6d5274f051631a56a0b3146cc0c3b5cc3d82f4e02d92f35ae","path":"index.js","sha256":"d10b03a38f8bddea0dceb4ee1ab4d9baa4b3e0a1e9ed08d7e9821dec1b4df338"}],"package_integrity":[{"filename":"fabric-native-loader-1.0.0.tgz","hashes":{"sha512_sri":"sha512-u4a1UHRdSmLMOi/QXgLJkopIbE/btoeXEUDzkJuDWcXGU+DeZAWngTZw6cDKZk2TPxs/3iUB7aJcM1+uxItYsg==","sha1":"2a94151dd544dc022f74563c19e7eeccc0081af1"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-native-loader/MAL-2026-17232.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}