MAL-2026-17232
Malicious code in fabric-native-loader (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (d289ae71736f05158f45d6636730641e82b5a774bf99bf1b587155d31c73daaa) package.json declares a postinstall hook that runs index.js on npm install. index.js reads Minecraft launcher credential stores (launcher_accounts.json, launcher_profiles.json, and equivalent files for Prism, MultiMC, TLauncher, Modrinth, PolyMC, GDLauncher), extracting Mojang/Microsoft accessTokens, refreshTokens, and clientTokens. It also recursively walks the.minecraft directory reading.json/.txt/.cfg/.properties/.yml/.log files and matches their contents against JWT and Bearer-token regexes. The collected credentials are combined with os.hostname(), os.userInfo().username, and os.platform() and POSTed via HTTPS to a hardcoded Discord webhook (discord.com/api/webhooks/1554065488726990909/...). No functionality matching the package name is present; the sole effect of installing the package is credential theft against the installer.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for fabric-native-loader (npm). Pin to a known-safe version or switch to an alternative.