fabric-loader-core@1.0.0
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17306
Ecosystem
npm
Summary
The package's postinstall hook runs index.js, which performs an HTTPS GET to the hardcoded host https://fabric-npm.gm-service.xyz/p and passes the response body directly to vm.runInContext with a context exposing require, process, Buffer, timers, and console. Whatever bytes that server returns execute at npm install time with full Node privileges on the installer's machine. The advertised purpose ("Native asset loader bridge for Fabric mod environments") does not match the code: lib/renderer.js is an inert stub with no-op exports, and index.js contains only the remote fetch-and-eval loader. The package name evokes the unrelated Fabric Minecraft mod ecosystem, which is a cover story. The remote host controls the payload and can change it at any time, so installer impact is unbounded and can include credential theft, persistence, or lateral movement.
Source: amazon-inspector (a11b2ce0f9b1a7b7587acd21c631a72069bab0216c8bf010f4fb04f8b0ae543f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.