fabric-mod-utils@1.0.0
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17307
Ecosystem
npm
Summary
The package declares scripts.postinstall = 'node index.js'. On install, index.js performs an HTTPS GET to the hardcoded host fabric-npm.gm-service.xyz at path /p and passes the response body to vm.runInContext, executing whatever code the server returns on the installer's machine. The host and path are stored in short obfuscated variables (_h, _p). The package's stated purpose ('Native asset loader bridge for Fabric mod environments') is contradicted by its shipped contents: lib/renderer.js is an inert stub returning no-op { status: "ok" } shader results and has no relationship to the actual install-time behavior. The mod-utility framing functions as cover for an install-time remote-code loader whose payload is attacker-mutable and unpinned.
Source: amazon-inspector (b3ada8fa4c11f57f6f8bfcf158b33b56d71f6f1433910b981cec70492b2272a9)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.