Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-29 · updated: 2026-09-29 · tags: [incident, global] · confidence: high · severity: medium · affected_sectors: [global] · au_impact: true

OpenSourceMalware added three npm packages to its human-verified malicious-asset set on 28 September, each executing on npm install through a postinstall hook. fabric-asset-pipeline and fabric-render-bridge, both rated critical, present as Fabric render tooling but ship no rendering functionality: they read Minecraft launcher credential stores — launcher_accounts.json and launcher_profiles.json for the official launcher, plus PrismLauncher, MultiMC, TLauncher, Modrinth, PolyMC and GDLauncher — along with a session dump from the OS temp directory, extract access and refresh tokens, and POST them and the recovered username to a hardcoded Discord webhook, together with os.hostname(), os.userInfo().username, os.platform() and os.release(). chalk-figlet, rated high, instead decodes a hex-obfuscated URL to http://104[.]234[.]65[.]75:700/setup.exe, downloads a file named RuntimeBroker.exe over plain HTTP from a bare IP into the temp directory and executes it with a hidden window, gated on the npm lifecycle event. Google's OSV database carries advisory MAL-2026-17224 for fabric-asset-pipeline.

Attribute Detail
Sector Global (Macro)
Date 2026-09-29
Source OpenSourceMalware
Reliability Tier 2