npm · Malicious package advisory
Malwarefabric-render-bridge
GHSA-r54m-4q33-rjvr
Malicious code in fabric-render-bridge (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (c2715ef0b07fbf0ca24fb8dadec44f2fcfdc273421a49ad2201bf8e40d3e2c01) package.json declares postinstall="node index.js", so `npm install fabric-render-bridge` automatically executes index.js. index.js reads Minecraft launcher credential stores across multiple launchers (launcher_accounts.json and launcher_profiles.json for the official launcher, PrismLauncher, MultiMC, TLauncher, Modrinth, PolyMC, GDLauncher) plus a session dump from the OS temp directory, extracts accessToken/refreshToken values and account usernames, and POSTs them via https.request to a hardcoded Discord webhook at discord.com/api/webhooks/1554065488726990909/. A separate sendInfo() routine POSTs os.hostname(), os.userInfo().username, os.platform() and os.release() to the same webhook on every install. The package presents itself as a Fabric render bridge but ships no rendering functionality; its sole install-time behavior is credential and host-identity theft. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/9c4594ea270f8ce1185755115d5eb811c41d8589/osv/malicious/npm/fabric-render-bridge/MAL-2026-17225.json)) **References:** - https://github.com/ossf/malicious-packages/blob/9c4594ea270f8ce1185755115d5eb811c41d8589/osv/malicious/npm/fabric-render-bridge/MAL-2026-17225.json - https://www.npmjs.com/package/fabric-render-bridge/v/1.0.0 - https://github.com/advisories/GHSA-r54m-4q33-rjvr
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.