OpenSSF/OSV advisory MAL-2026-17225 confirms this npm version as malicious. package.json declares postinstall="node index.js", so `npm install fabric-render-bridge` automatically executes index.js. index.js reads Minecraft launcher credential stores across multiple launchers (launcher_accounts.json and launcher_profiles.json for the official launcher, PrismLauncher, MultiMC, TLauncher, Modrinth, PolyMC, GDLauncher) plus a session dump from the OS temp directory, extracts...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in fabric-render-bridge (npm)
Details
package.json declares postinstall="node index.js", so `npm install fabric-render-bridge` automatically executes index.js. index.js reads Minecraft launcher credential stores across multiple launchers (launcher_accounts.json and launcher_profiles.json for the official launcher, PrismLauncher, MultiMC, TLauncher, Modrinth, PolyMC, GDLauncher) plus a session dump from the OS temp directory, extracts accessToken/refreshToken values and account usernames, and POSTs them via https.request to a hardcoded Discord webhook at discord.com/api/webhooks/1554065488726990909/. A separate sendInfo() routine POSTs os.hostname(), os.userInfo().username, os.platform() and os.release() to the same webhook on every install. The package presents itself as a Fabric render bridge but ships no rendering functionality; its sole install-time behavior is credential and host-identity theft.
Decision reason
OpenSSF Malicious Packages via OSV confirms fabric-render-bridge@1.0.0 as malicious (MAL-2026-17225): Malicious code in fabric-render-bridge (npm)