Open Source · · 38 days

Treecapitator plugin shipped Fracturiser malware

An account with publishing rights on BukkitDev for a popular plugin implementing 'Treecapitator' functionality was compromised. A malicious JAR file containing the 'Fracturiser' malware was uploaded, appearing as an update.

Part of Fractureiser mod campaign stole player credentials campaign

Treecapitator shows why Fracturiser was not only a CurseForge problem. The affected distribution surface was BukkitDev, another trusted route for Minecraft server plugins.

The attacker used publishing rights for a familiar plugin name and uploaded a malicious JAR as though it were a normal update. Server operators and players were conditioned to trust that path. The payload matched the wider Fracturiser chain: a Java entry point inside a mod or plugin archive, followed by staged malware aimed at credentials and host compromise on Windows and Linux systems.

The BukkitDev angle widened the response problem. Defenders could not limit their search to CurseForge modpacks; they also had to check plugin folders and server-side JARs that might execute under a different Minecraft workflow.

This record is kept separate because the package scope and platform differ. The campaign groups the shared malware family; the Treecapitator entry records the Bukkit plugin distribution path responders needed to search.

Notes

  • The exact Treecapitator JAR hash is unpublished. A bounded shared Fractureiser stage-chain fragment is retained under samples/ as report evidence, explicitly without reconstructing the plugin JAR or any malware stage.

Appendix · Affected releases

Treecapitator (Bukkit Plugin)
  • No per-file hash is published for this project. An identical SHA-256 was previously recorded here and on three sibling mod records, which cannot all be the same JAR, and it appears in none of the cited sources, so it was removed.

References

  1. June 2023 - Infected mods detection toolsupport.curseforge.com
  2. CurseForge compromised mods alertprismlauncher.org
  3. Infected Minecraft mods lead to multi-stage, multi-platform infostealer malwarebitdefender.com

Source record: oss/attacks/treecapitator/meta.yaml