Open Source · · 38 days

Simply Houses mod shipped Fracturiser malware

A developer account (shyandlostboy81) with publishing rights for the 'Simply Houses' Minecraft mod on CurseForge was compromised. Attackers uploaded a malicious JAR file disguised as a legitimate update.

Part of Fractureiser mod campaign stole player credentials campaign

Simply Houses was a direct Fracturiser distribution point. A CurseForge account with rights to publish the mod was compromised, and the attacker used that authority to upload a JAR that looked like a normal project update.

The malicious artifact carried the shared Fracturiser stage seen across the campaign. The first-stage code ran in the Minecraft mod-loading path, then pulled the infection chain toward host-level credential theft.

The package scope is narrow, but useful. Players looking at a large campaign need to know whether a mod they installed was one of the concrete affected names, and Simply Houses was named in public response material. The response path was the same as the wider campaign: remove affected JARs, scan for active infection, and treat dormant downloaded mods as dangerous until checked.

The campaign record carries the broad mechanics; this record anchors the specific project so inventories, launcher profiles, and server mod folders can be checked against a concrete name.

Notes

  • The exact Simply Houses JAR hash is unpublished. A bounded shared Fractureiser stage-chain fragment is retained under samples/ as report evidence, explicitly without reconstructing the project JAR or any malware stage.

Appendix · Affected releases

Simply Houses
  • A complete pre-incident Modrinth build is retained as a clean comparator.
  • No per-file hash is published for this project. An identical SHA-256 was previously recorded here and on three sibling mod records, which cannot all be the same JAR, and it appears in none of the cited sources, so it was removed.

References

  1. June 2023 - Infected mods detection toolsupport.curseforge.com
  2. Fractureiser Malwaremineacademy.org
  3. Infected Minecraft mods lead to multi-stage, multi-platform infostealer malwarebitdefender.com

Source record: oss/attacks/simply-houses/meta.yaml