fabric-asset-pipeline@1.0.1
Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 8:08 PM UTC
OSV ID
MAL-2026-17224
Ecosystem
npm
Summary
fabric-asset-pipeline@1.0.0 declares a postinstall hook that runs index.js on npm install. index.js is heavily obfuscated (obfuscator.io-style rotated string array plus base64+RC4 decoding of identifiers and URLs, with newline/regex anti-formatting hooks) and implements a Minecraft credential stealer: functions stealLauncherAccounts(), stealAltLaunchers(), and readSessionDump() read account credential stores from the official Minecraft launcher (launcher_accounts.json / launcher_profiles.json) as well as Prism/MultiMC, TLauncher, Modrinth, PolyMC, and GDLauncher, plus a session dump from the OS temp directory. Extracted account names, access tokens, and refresh tokens are POSTed via https.request to a hardcoded webhook whose URL is RC4-decoded at runtime. A companion sendInfo() call ships os.hostname(), os.userInfo().username, os.platform()/os.release(), and the recovered Minecraft username to the same endpoint. None of this behavior is part of the package's advertised 'asset loader bridge' purpose, and the obfuscation deliberately conceals both the exfiltration functions and the destination URL.
Source: amazon-inspector (bb92787d766d5bfa0c384cc04909689215fa0d3e869630422caa8bedd303038a)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.