Native asset loader bridge for Fabric mod environments
An install-time hook collects Minecraft account data and token-like values, then transmits a report to a Discord webhook. This is a confirmed credential and data exfiltration path.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkg · L3Source appears to send environment or credential material to an external endpoint.
index.jsView on unpkg · L3A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkg · L3A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
index.jsView on unpkg · L3This report applies to fabric-native-loader@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkg · L3Source appears to send environment or credential material to an external endpoint.
index.jsView on unpkg · L3A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkg · L3A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
index.jsView on unpkg · L3