OpenSourceMalware added three npm packages to its human-verified malicious-asset set on 28 September, each executing on npm install through a postinstall hook. fabric-asset-pipeline and fabric-render-bridge, both rated critical, present as Fabric render tooling but ship no rendering functionality: they read Minecraft launcher credential stores — launcher_accounts.json and launcher_profiles.json for the official launcher, plus PrismLauncher, MultiMC, TLauncher, Modrinth, PolyMC and GDLauncher — along with a session dump from the OS temp directory, extract access and refresh tokens, and POST them and the recovered username to a hardcoded Discord webhook, together with os.hostname(), os.userInfo().username, os.platform() and os.release(). chalk-figlet, rated high, instead decodes a hex-obfuscated URL to http://104[.]234[.]65[.]75:700/setup.exe, downloads a file named RuntimeBroker.exe over plain HTTP from a bare IP into the temp directory and executes it with a hidden window, gated on the npm lifecycle event. Google's OSV database carries advisory MAL-2026-17224 for fabric-asset-pipeline.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-29 |
| Source | OpenSourceMalware |
| Reliability | Tier 2 |