Logo
npm

fabric-loader-core@1.0.0

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17306

Ecosystem

npm

Summary

The package's postinstall hook runs index.js, which performs an HTTPS GET to the hardcoded host https://fabric-npm.gm-service.xyz/p and passes the response body directly to vm.runInContext with a context exposing require, process, Buffer, timers, and console. Whatever bytes that server returns execute at npm install time with full Node privileges on the installer's machine. The advertised purpose ("Native asset loader bridge for Fabric mod environments") does not match the code: lib/renderer.js is an inert stub with no-op exports, and index.js contains only the remote fetch-and-eval loader. The package name evokes the unrelated Fabric Minecraft mod ecosystem, which is a cover story. The remote host controls the payload and can change it at any time, so installer impact is unbounded and can include credential theft, persistence, or lateral movement.

Source: amazon-inspector (a11b2ce0f9b1a7b7587acd21c631a72069bab0216c8bf010f4fb04f8b0ae543f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.