Campaign · Open Source · · 19 days
Fractureiser mod campaign stole player credentials
Fractureiser spread through single-use uploader accounts and one compromised studio account in 2023, turning trusted CurseForge and Bukkit distribution paths into malware delivery channels.
Draws together 5 incidents across 9 packages
Fractureiser moved through the social and technical machinery of Minecraft modding. Most of the malicious files came from single-use accounts with autogenerated names, uploading new projects rather than hijacking established ones; exactly one established uploader, Luna Pixel Studios, was compromised. CurseForge stated that the platform itself was not breached and no admin account was taken. That distribution path gave the campaign a long reach: a player did not need to visit a suspicious site or install a fake project, because a trusted CurseForge or Bukkit page, a familiar maintainer name, or a modpack dependency graph could carry the first stage.
The payload chain targeted Windows and Linux systems, and it replicated: the third stage walked the whole filesystem and infected every jar that looked like a mod, including Gradle and Maven caches, so a developer who merely built a project could ship the malware onward. Detection guidance split the problem in two, active host infection and dormant infected JARs, which mattered because a downloaded mod archive could sit quietly in a mods folder until Minecraft or a server loader executed it.
CurseForge banned accounts tied to the uploads, published detection tooling, and maintained a list of affected projects. Community investigators separately mapped stages, hashes, indicators, and cleanup steps as the campaign unfolded.
The incident was not one poisoned package. It was a distribution-path failure across a creator ecosystem, where trust attached to project names, maintainer accounts, and modpack dependency graphs.
Notes
- The malware is spelled "fractureiser" in both references, after the CurseForge account that uploaded the most notable files. The record id retains the earlier misspelling so existing links keep working.
- The start date follows the investigation timeline, which places the earliest confirmed malicious files on 20 May 2023. Files dated April were also found, and the investigators note the dates may be spoofed, so the campaign may be older.
Incidents in this campaign
Appendix · Affected packages
Samples and hashes sit on each incident page, linked above
References
- June 2023 - Infected mods detection toolsupport.curseforge.com
- fractureiser investigationgithub.com
Source record: oss/campaigns/fracturiser-2023/meta.yaml