MAL-2026-17224
Malicious code in fabric-asset-pipeline (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (bb92787d766d5bfa0c384cc04909689215fa0d3e869630422caa8bedd303038a) fabric-asset-pipeline@1.0.0 declares a postinstall hook that runs index.js on npm install. index.js is heavily obfuscated (obfuscator.io-style rotated string array plus base64+RC4 decoding of identifiers and URLs, with newline/regex anti-formatting hooks) and implements a Minecraft credential stealer: functions stealLauncherAccounts(), stealAltLaunchers(), and readSessionDump() read account credential stores from the official Minecraft launcher (launcher_accounts.json / launcher_profiles.json) as well as Prism/MultiMC, TLauncher, Modrinth, PolyMC, and GDLauncher, plus a session dump from the OS temp directory. Extracted account names, access tokens, and refresh tokens are POSTed via https.request to a hardcoded webhook whose URL is RC4-decoded at runtime. A companion sendInfo() call ships os.hostname(), os.userInfo().username, os.platform()/os.release(), and the recovered Minecraft username to the same endpoint. None of this behavior is part of the package's advertised 'asset loader bridge' purpose, and the obfuscation deliberately conceals both the exfiltration functions and the destination URL.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for fabric-asset-pipeline (npm). Pin to a known-safe version or switch to an alternative.