Open Source · · 7 days
Better MC modpacks shipped Fracturiser malware
The CurseForge account for 'Luna Pixel Studios', creators of the very popular 'Better MC' modpack series, was compromised. Attackers uploaded malicious versions of the modpacks (e.g., BMC3 for Forge 1.19.2).
Part of Fractureiser mod campaign stole player credentials campaign
Better MC mattered because it was a modpack, not a single small mod. No attacker logged into Luna Pixel Studios' account. A developer there tried out one of the malicious uploads, fractureiser infected the jars on that machine, and the studio published the result as trusted bundles. The named affected scope included Better MC Forge BMC3, Better MC Forge BMC2, and Better MC Fabric, packages that pulled together many mods under a familiar project name, so the malicious upload inherited trust from both the modpack brand and its dependency graph.
Fractureiser used the Minecraft loader path as execution. Once a poisoned JAR was loaded, the staged malware reached beyond the game and targeted host data on Windows and Linux, including secrets useful for accounts and for further spread.
The cleanup problem was therefore not just "remove one mod." Players had to treat the whole affected modpack install as suspect, then scan for active infection and for dormant JARs that could restart the chain later.
This record stays separate from the campaign because Better MC was one of the high-signal package scopes. The campaign explains the shared malware; this record preserves the concrete releases players were told to remove and scan around.
Appendix · Affected releases
- The malware that rode inside the Better MC uploads, recorded as its own artifact because the modpack files cannot be acquired. A stage 0 jar loads a class named Utility over plain HTTP from 85.217.144.130:8080/dl and calls run() on it.
- Luna Pixel Studios was infected by testing one of these seed mods, so this is the upstream of the Better MC compromise rather than a separate incident.
- Modrinth's exact clean DungeonZ 1.0.1 build for Minecraft 1.19.2 is retained as a complete comparator for the infected jar with the same embedded mod version and target.
- One of the named Better MC examples from the compromised Luna Pixel Studios account; shared Fracturiser stage hashes remain at the attack level.
- Named affected modpack release; exact file URL is not captured in the current record.
- Named affected modpack release; exact file URL is not captured in the current record.
- The Luna Pixel Studios mod that actually carried the infection under their own account. The investigation team records that Luna Pixel Studios was compromised after a developer tested one of the attacker's seed mods.
- Its injected method sits in com.bmc.coremod.BMCSkyblockCore, the Better MC core mod, which is what ties this file to this record rather than to the seed uploads.
Indicators
- hashsha1:dc43c4685c3f47808ac207d1667cc1eb915b2d82
- hashsha1:52d08736543a240b0cbbbf2da03691ae525bb119
- hashsha1:6ec85c8112c25abe4a71998eb32480d266408863
- hashsha1:c2d0c87a1fe99e3c44a52c48d8bcf65a67b3e9a5
- hashsha1:e299bf5a025f5c3fff45d017c3c2f467fa599915
References
- June 2023 - Infected mods detection toolsupport.curseforge.com
- New Fractureiser malware used CurseForge Minecraft mods to infect Windows, Linuxbleepingcomputer.com
- Some CurseForge accounts might be compromisedreddit.com
- Fractureiser technical detailsraw.githubusercontent.com
Source record: oss/attacks/better-mc/meta.yaml