OpenSSF/OSV advisory MAL-2026-17306 confirms this npm version as malicious. The package's postinstall hook runs index.js, which performs an HTTPS GET to the hardcoded host https://fabric-npm.gm-service.xyz/p and passes the response body directly to vm.runInContext with a context exposing require, process, Buffer, timers, and console. Whatever bytes that server returns execute at npm install time with full Node privileges on the installer's machine...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThis report applies to fabric-loader-core@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg