{"id":"MAL-2026-17306","summary":"Malicious code in fabric-loader-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a11b2ce0f9b1a7b7587acd21c631a72069bab0216c8bf010f4fb04f8b0ae543f)\nThe package's postinstall hook runs index.js, which performs an HTTPS GET to the hardcoded host https://fabric-npm.gm-service.xyz/p and passes the response body directly to vm.runInContext with a context exposing require, process, Buffer, timers, and console. Whatever bytes that server returns execute at npm install time with full Node privileges on the installer's machine. The advertised purpose (\"Native asset loader bridge for Fabric mod environments\") does not match the code: lib/renderer.js is an inert stub with no-op exports, and index.js contains only the remote fetch-and-eval loader. The package name evokes the unrelated Fabric Minecraft mod ecosystem, which is a cover story. The remote host controls the payload and can change it at any time, so installer impact is unbounded and can include credential theft, persistence, or lateral movement.\n","modified":"2026-09-30T01:45:10.576976578Z","published":"2026-09-30T01:25:34Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-30T01:25:34Z","sha256":"a11b2ce0f9b1a7b7587acd21c631a72069bab0216c8bf010f4fb04f8b0ae543f","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020779","import_time":"2026-09-30T01:36:50.955619578Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/fabric-loader-core/v/1.0.0"}],"affected":[{"package":{"name":"fabric-loader-core","ecosystem":"npm","purl":"pkg:npm/fabric-loader-core"},"versions":["1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"615f67404e631a9c5c2f81442b2b99e615e19d3e7803e4436dfcd3e49f46fbc7","tlsh":"2ef0dd36bbed6125272054eca4838806c86be2232212f690f69c42586fca53cf1d6798","path":"index.js"},{"sha256":"64b4532f14010e3f8afbb92102d3c3fcf1d1756618d958d9052938c60337febb","tlsh":"25e0cd206a20d62320d4d7705e36495536204f1b4044bc6d61a7115cd3ce77545fb35b","path":"package.json"}],"package_integrity":[{"hashes":{"sha1":"3f5accb342b941a348c57b9b9912b5c94cc3fb05","sha512_sri":"sha512-IE/e13oz87A/GBxkHw/24iCRWeW4fnXQ41P8x1S462slG8//wZ5PRDpwpGit+RnkY6pPVNf6fkn/jQ2SUmafMw=="},"filename":"fabric-loader-core-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-loader-core/MAL-2026-17306.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}