VDB
GCVE-110-OSM-2026-12681
GCVE-110-OSM-2026-12681
Advisory PublishedCVSS 9.6/10
fabric-asset-pipeline@1.0.0 declares a postinstall hook that runs index.js on npm install. index.js is heavily obfuscated (obfuscator.io-style rotated string array plus base64+RC4 decoding of identifiers and URLs, with newline/regex anti-formatting hooks) and implements a Minecraft credential stealer: functions stealLauncherAccounts(), stealAltLaunchers(), and readSessionDump() read account credential stores from the official Minecraft launcher (launcher_accounts.json / launcher_profiles.json) as well as Prism/MultiMC, TLauncher, Modrinth, PolyMC, and GDLauncher, plus a session dump from the OS temp directory. Extracted account names, access tokens, and refresh tokens are POSTed via https.request to a hardcoded webhook whose URL is RC4-decoded at runtime. A companion sendInfo() call ships os.hostname(), os.userInfo().username, os.platform()/os.release(), and the recovered Minecraft username to the same endpoint. None of this behavior is part of the package's advertised 'asset loader bridge' purpose, and the obfuscation deliberately conceals both the exfiltration functions and the destination URL.
ENTRY
index.js (install-hook: node index.js)
- Install Hook Executes Local JS File in package.json
PERSISTENCE
- Startup Persistence in index.js: ".profile"
DESTINATION
- 3 exfil (discord-webhook, custom-c2)
(values recorded in verified_iocs)
EXFIL
- Network Request in index.js: "https.request("
- System Information Collection in index.js: "os.userInfo()"
OBFUSCATION
- Decoded Base64 Content in index.js
- Base64 Encoded Payload in index.js: ""aHR0cHM6Ly9kaXNjb3JkLmNvbS9hcGkvd2ViaG9va3MvMTU1NDA2NTQ4ODcyNjk5MDkwOS9UQmRUbko..."
- recovered 1 urls, 1 domains, 1 discordWebhooks from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
PAYLOAD FILES
index.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | fabric-asset-pipeline | all (affected) | — |
Aliases
Browse GCVE Records
3,112 records in the GCVE database · Updated October 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.