Open Source · · 7 days
Better MC modpacks shipped Fracturiser malware
The CurseForge account for 'Luna Pixel Studios', creators of the very popular 'Better MC' modpack series, was compromised. Attackers uploaded malicious versions of the modpacks (e.g., BMC3 for Forge 1.19.2).
Part of Fracturiser mod campaign stole player credentials campaign
Better MC mattered because it was a modpack, not a single small mod. A compromised Luna Pixel Studios publishing account let attackers place Fracturiser into releases that players installed as trusted bundles. The named affected scope included Better MC Forge BMC3, Better MC Forge BMC2, and Better MC Fabric, packages that pulled together many mods under a familiar project name, so the malicious upload inherited trust from both the modpack brand and its dependency graph.
Fracturiser used the Minecraft loader path as execution. Once a poisoned JAR was loaded, the staged malware reached beyond the game and targeted host data on Windows and Linux, including secrets useful for accounts and for further spread.
The cleanup problem was therefore not just "remove one mod." Players had to treat the whole affected modpack install as suspect, then scan for active infection and for dormant JARs that could restart the chain later.
This record stays separate from the campaign because Better MC was one of the high-signal package scopes. The campaign explains the shared malware; this record preserves the concrete releases players were told to remove and scan around.
Appendix · Affected releases
- One of the named Better MC examples from the compromised Luna Pixel Studios account; shared Fracturiser stage hashes remain at the attack level.
- Named affected modpack release; exact file URL is not captured in the current record.
- Named affected modpack release; exact file URL is not captured in the current record.
Indicators
- hashsha1:dc43c4685c3f47808ac207d1667cc1eb915b2d82
- hashsha1:52d08736543a240b0cbbbf2da03691ae525bb119
- hashsha1:6ec85c8112c25abe4a71998eb32480d266408863
- hashsha1:c2d0c87a1fe99e3c44a52c48d8bcf65a67b3e9a5
- hashsha1:e299bf5a025f5c3fff45d017c3c2f467fa599915
References
- June 2023 - Infected mods detection toolsupport.curseforge.com
- New Fractureiser malware used CurseForge Minecraft mods to infect Windows, Linuxbleepingcomputer.com
- Some CurseForge accounts might be compromisedreddit.com
- Fractureiser technical detailsraw.githubusercontent.com
Source record: oss/attacks/better-mc/meta.yaml