Malicious code in fabric-native-loader (npm)
The npm package fabric-native-loader version 1.0.0 contains malicious code that executes during installation. It steals Minecraft launcher credentials and related tokens from various launcher files and system information, then sends this data to a hardcoded Discord webhook. The package does not provide any legitimate functionality matching its name and solely acts to exfiltrate sensitive user credentials.
AI Analysis
Technical Summary
The fabric-native-loader npm package (version 1.0.0) includes a postinstall script that runs index.js upon installation. This script reads credential files from multiple Minecraft launchers (including launcher_accounts.json and launcher_profiles.json) to extract Mojang/Microsoft accessTokens, refreshTokens, and clientTokens. It also scans the .minecraft directory for files containing JWT and Bearer tokens. The collected credentials, along with system information such as hostname, username, and platform, are sent via HTTPS POST to a hardcoded Discord webhook URL. The package contains no legitimate functionality and is solely designed for credential theft.
Potential Impact
Installation of this package results in the theft of Minecraft launcher credentials and associated tokens, potentially allowing unauthorized access to affected user accounts. The exfiltrated data includes sensitive authentication tokens and system identifiers, which could be used for account compromise or further malicious activity.
Mitigation Recommendations
No official patch or remediation is indicated. Users should avoid installing the fabric-native-loader package version 1.0.0. If installed, users should assume their Minecraft credentials may be compromised and take appropriate actions such as changing passwords and revoking tokens. Monitor for any updates or advisories from trusted sources regarding this package.
Malicious code in fabric-native-loader (npm)
Description
The npm package fabric-native-loader version 1.0.0 contains malicious code that executes during installation. It steals Minecraft launcher credentials and related tokens from various launcher files and system information, then sends this data to a hardcoded Discord webhook. The package does not provide any legitimate functionality matching its name and solely acts to exfiltrate sensitive user credentials.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The fabric-native-loader npm package (version 1.0.0) includes a postinstall script that runs index.js upon installation. This script reads credential files from multiple Minecraft launchers (including launcher_accounts.json and launcher_profiles.json) to extract Mojang/Microsoft accessTokens, refreshTokens, and clientTokens. It also scans the .minecraft directory for files containing JWT and Bearer tokens. The collected credentials, along with system information such as hostname, username, and platform, are sent via HTTPS POST to a hardcoded Discord webhook URL. The package contains no legitimate functionality and is solely designed for credential theft.
Potential Impact
Installation of this package results in the theft of Minecraft launcher credentials and associated tokens, potentially allowing unauthorized access to affected user accounts. The exfiltrated data includes sensitive authentication tokens and system identifiers, which could be used for account compromise or further malicious activity.
Mitigation Recommendations
No official patch or remediation is indicated. Users should avoid installing the fabric-native-loader package version 1.0.0. If installed, users should assume their Minecraft credentials may be compromised and take appropriate actions such as changing passwords and revoking tokens. Monitor for any updates or advisories from trusted sources regarding this package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-17232
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6abb4187f7a7c54106cc2f8d
Added to database: 09/29/2026, 04:41:43 UTC
Last enriched: 09/29/2026, 04:47:35 UTC
Last updated: 09/29/2026, 10:20:59 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.