Open Source · · 38 days
Sky Villages mod shipped Fracturiser malware
The CurseForge account associated with the 'Sky Villages' Minecraft mod was compromised. Attackers uploaded a malicious JAR file appearing as a legitimate update for the mod.
Part of Fracturiser mod campaign stole player credentials campaign
Sky Villages was one of the named Fracturiser carrier projects on CurseForge. The attacker did not need to invent a fake package; the trusted project page and maintainer path were enough.
The malicious upload arrived as a JAR update for the Forge and Fabric mod. When loaded by Minecraft, it gave the first Fracturiser stage a clean execution point inside the player's expected mod workflow. From there the campaign chain moved outside the game: public analyses describe multi-stage malware that targeted Windows and Linux hosts and focused on secrets, persistence, and further compromise rather than visible game disruption.
That quietness was the core risk. A player could install or update Sky Villages for ordinary gameplay reasons and only discover the problem later, after the loader had used a normal mod startup path.
This record preserves the project-specific distribution surface. The campaign record explains the shared infrastructure; the artifact here names the CurseForge page players and responders had to check.
Appendix · Affected releases
References
- June 2023 - Infected mods detection toolsupport.curseforge.com
- Fracturiser supply chain attack infecting Minecraft modssecurelist.com
- Dozens of popular Minecraft mods found infected with Fracturiser malwarearstechnica.com
- Fractureiser Investigation Repositorygithub.com
- New Fractureiser malware used CurseForge Minecraft mods to infect Windows, Linuxbleepingcomputer.com
Source record: oss/attacks/sky-villages/meta.yaml