{"id":"MAL-2026-17307","summary":"Malicious code in fabric-mod-utils (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b3ada8fa4c11f57f6f8bfcf158b33b56d71f6f1433910b981cec70492b2272a9)\nThe package declares scripts.postinstall = 'node index.js'. On install, index.js performs an HTTPS GET to the hardcoded host fabric-npm.gm-service.xyz at path /p and passes the response body to vm.runInContext, executing whatever code the server returns on the installer's machine. The host and path are stored in short obfuscated variables (_h, _p). The package's stated purpose ('Native asset loader bridge for Fabric mod environments') is contradicted by its shipped contents: lib/renderer.js is an inert stub returning no-op { status: \"ok\" } shader results and has no relationship to the actual install-time behavior. The mod-utility framing functions as cover for an install-time remote-code loader whose payload is attacker-mutable and unpinned.\n","modified":"2026-09-30T01:45:10.589921854Z","published":"2026-09-30T01:26:57Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020783","import_time":"2026-09-30T01:36:51.27049627Z","modified_time":"2026-09-30T01:26:57Z","sha256":"b3ada8fa4c11f57f6f8bfcf158b33b56d71f6f1433910b981cec70492b2272a9","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/fabric-mod-utils/v/1.0.0"}],"affected":[{"package":{"name":"fabric-mod-utils","ecosystem":"npm","purl":"pkg:npm/fabric-mod-utils"},"versions":["1.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"2ef0dd36bbed6125272054eca4838806c86be2232212f690f69c42586fca53cf1d6798","path":"index.js","sha256":"615f67404e631a9c5c2f81442b2b99e615e19d3e7803e4436dfcd3e49f46fbc7"},{"sha256":"1d8f63500bc105cf989bf26d6993f45718b0e1ebb9a57e013e7b0b4670119414","tlsh":"bde0c2206a21da2320d8aab46e3a569536204f2b4044fcac22a7115cd2cebb655fb31b","path":"package.json"}],"package_integrity":[{"filename":"fabric-mod-utils-1.0.0.tgz","hashes":{"sha512_sri":"sha512-5ICIheYaEQGlvKlCbedZtSeCxT/UQPkdOcbM1/n/nwqv+A5Yd1SYiIm3IOlkTsVIUHmtJ3d1sFQBUgG2Uh0Dkw==","sha1":"4112b38907ddf649328e4620f93f9434c1f4af76"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fabric-mod-utils/MAL-2026-17307.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}