Skip to main content

Malicious code in fabric-native-loader (npm)

0
High
Published: 09/28/2026 (09/28/2026, 22:04:12 UTC)
Source: GCVE Database
Product: fabric-native-loader

Description

The npm package fabric-native-loader version 1.0.0 contains malicious code that executes during installation. It steals Minecraft launcher credentials and related tokens from various launcher files and system information, then sends this data to a hardcoded Discord webhook. The package does not provide any legitimate functionality matching its name and solely acts to exfiltrate sensitive user credentials.

Affected software

npmghsa
fabric-native-loader
Affected versions
=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 04:47:35 UTC

Technical Analysis

The fabric-native-loader npm package (version 1.0.0) includes a postinstall script that runs index.js upon installation. This script reads credential files from multiple Minecraft launchers (including launcher_accounts.json and launcher_profiles.json) to extract Mojang/Microsoft accessTokens, refreshTokens, and clientTokens. It also scans the .minecraft directory for files containing JWT and Bearer tokens. The collected credentials, along with system information such as hostname, username, and platform, are sent via HTTPS POST to a hardcoded Discord webhook URL. The package contains no legitimate functionality and is solely designed for credential theft.

Potential Impact

Installation of this package results in the theft of Minecraft launcher credentials and associated tokens, potentially allowing unauthorized access to affected user accounts. The exfiltrated data includes sensitive authentication tokens and system identifiers, which could be used for account compromise or further malicious activity.

Mitigation Recommendations

No official patch or remediation is indicated. Users should avoid installing the fabric-native-loader package version 1.0.0. If installed, users should assume their Minecraft credentials may be compromised and take appropriate actions such as changing passwords and revoking tokens. Monitor for any updates or advisories from trusted sources regarding this package.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-17232
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6abb4187f7a7c54106cc2f8d

Added to database: 09/29/2026, 04:41:43 UTC

Last enriched: 09/29/2026, 04:47:35 UTC

Last updated: 09/29/2026, 10:20:59 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses