Open Source · · 38 days

Simply Houses mod shipped Fracturiser malware

A developer account (shyandlostboy81) with publishing rights for the 'Simply Houses' Minecraft mod on CurseForge was compromised. Attackers uploaded a malicious JAR file disguised as a legitimate update.

Part of Fracturiser mod campaign stole player credentials campaign

Simply Houses was a direct Fracturiser distribution point. A CurseForge account with rights to publish the mod was compromised, and the attacker used that authority to upload a JAR that looked like a normal project update.

The malicious artifact carried the shared Fracturiser stage seen across the campaign. The first-stage code ran in the Minecraft mod-loading path, then pulled the infection chain toward host-level credential theft.

The package scope is narrow, but useful. Players looking at a large campaign need to know whether a mod they installed was one of the concrete affected names, and Simply Houses was named in public response material. The response path was the same as the wider campaign: remove affected JARs, scan for active infection, and treat dormant downloaded mods as dangerous until checked.

The campaign record carries the broad mechanics; this record anchors the specific project so inventories, launcher profiles, and server mod folders can be checked against a concrete name.