Campaign · Open Source · · 38 days
Fracturiser mod campaign stole player credentials
Fracturiser spread through compromised Minecraft mod and modpack publishing accounts in 2023, turning trusted CurseForge and Bukkit distribution paths into malware delivery channels.
Draws together 5 incidents across 7 packages
Fracturiser moved through the social and technical machinery of Minecraft modding. Attackers used compromised platform accounts and project uploads to put malicious JARs where players already went for mods, plugins, and modpacks. That distribution path gave the campaign a long reach: a player did not need to visit a suspicious site or install a fake project, because a trusted CurseForge or Bukkit page, a familiar maintainer name, or a modpack dependency graph could carry the first stage.
The payload chain targeted Windows and Linux systems. Detection guidance split the problem in two, active host infection and dormant infected JARs, which mattered because a downloaded mod archive could sit quietly in a mods folder until Minecraft or a server loader executed it.
CurseForge banned accounts tied to the uploads, published detection tooling, and maintained a list of affected projects. Community investigators separately mapped stages, hashes, indicators, and cleanup steps as the campaign unfolded.
The incident was not one poisoned package. It was a distribution-path failure across a creator ecosystem, where trust attached to project names, maintainer accounts, and modpack dependency graphs.
Incidents in this campaign
Appendix · Affected packages
Samples and hashes sit on each incident page, linked above
References
- June 2023 - Infected mods detection toolsupport.curseforge.com
- fractureiser investigationgithub.com
Source record: oss/campaigns/fracturiser-2023/meta.yaml