Campaign · Open Source · · 19 days

Fractureiser mod campaign stole player credentials

Fractureiser spread through single-use uploader accounts and one compromised studio account in 2023, turning trusted CurseForge and Bukkit distribution paths into malware delivery channels.

Draws together 5 incidents across 9 packages

Fractureiser moved through the social and technical machinery of Minecraft modding. Most of the malicious files came from single-use accounts with autogenerated names, uploading new projects rather than hijacking established ones; exactly one established uploader, Luna Pixel Studios, was compromised. CurseForge stated that the platform itself was not breached and no admin account was taken. That distribution path gave the campaign a long reach: a player did not need to visit a suspicious site or install a fake project, because a trusted CurseForge or Bukkit page, a familiar maintainer name, or a modpack dependency graph could carry the first stage.

The payload chain targeted Windows and Linux systems, and it replicated: the third stage walked the whole filesystem and infected every jar that looked like a mod, including Gradle and Maven caches, so a developer who merely built a project could ship the malware onward. Detection guidance split the problem in two, active host infection and dormant infected JARs, which mattered because a downloaded mod archive could sit quietly in a mods folder until Minecraft or a server loader executed it.

CurseForge banned accounts tied to the uploads, published detection tooling, and maintained a list of affected projects. Community investigators separately mapped stages, hashes, indicators, and cleanup steps as the campaign unfolded.

The incident was not one poisoned package. It was a distribution-path failure across a creator ecosystem, where trust attached to project names, maintainer accounts, and modpack dependency graphs.

Notes

  • The malware is spelled "fractureiser" in both references, after the CurseForge account that uploaded the most notable files. The record id retains the earlier misspelling so existing links keep working.
  • The start date follows the investigation timeline, which places the earliest confirmed malicious files on 20 May 2023. Files dated April were also found, and the investigators note the dates may be spoofed, so the campaign may be older.

Incidents in this campaign

  1. Simply Houses mod shipped Fracturiser malware
  2. Sky Villages mod shipped Fracturiser malware
  3. Treecapitator plugin shipped Fracturiser malware
  4. When Dungeons Arise shipped Fracturiser malware
  5. Better MC modpacks shipped Fracturiser malware

Appendix · Affected packages

Simply Houses 2023-05-01 to 2023-06-08
Sky Villages [Forge/Fabric] 2023-05-01 to 2023-06-08
Treecapitator (Bukkit Plugin) 2023-05-01 to 2023-06-08
When Dungeons Arise 2023-05-01 to 2023-06-08
fractureiser stage 0 infected mod jar 2023-04-01 to 2023-06-08
Better MC [Forge] - BMC3 2023-06-01 to 2023-06-08
v18
Better MC [Forge] - BMC2 2023-06-01 to 2023-06-08
v7
Better MC [FABRIC] 2023-06-01 to 2023-06-08
v10
skyblock-core 2023-06-01 to 2023-06-08

Samples and hashes sit on each incident page, linked above

References

  1. June 2023 - Infected mods detection toolsupport.curseforge.com
  2. fractureiser investigationgithub.com

Source record: oss/campaigns/fracturiser-2023/meta.yaml