Minecraft Malware Spreading Through Mods, Plug-ins

A worm virus called "fracturizer" has been embedded in modpacks from various sites, including CurseForge and CraftBukkit.

Dark Reading Staff, Dark Reading

June 7, 2023

1 Min Read
Minecraft player
Source: Lenscap via Alamy Stock Photo

Minecraft players should hold off on downloading any new mods or plugins while cybersecurity researchers try to track down a fix for malware ripping through the game.

A worm virus named "fracturizer" has been found embedded in popular Minecraft modpacks, several game themes pulled together, which are then used by players to toggle between multiple mods, giving the player more experience options, as well as helping the malware spread.

The fracturizer GitHub repository characterizes the malware as "incredibly dangerous" and adds that any infected machine should be assumed to be completely compromised by the threat actors behind the virus.

Contributing GitHub researchers found the malicious files going back for some time, with files dated back to April, as well as some files dated from 1999, a quirk with CurseForge they found notable.

CurseForge assured users in a statement added to the fracturizer GitHub page on June 7 that it is not compromised and has suspended accounts linked to the malware. The CurseForge added that its team is working on a fix.

GitHub also noted a command-and-control server linked to fracturizer has been was suspended by its hosting provider.

Minecraft mod players who want to check if they have been exposed to fracturizer can refer to a set of specific instructions on GitHub to look for indicators of compromise and take mitigation steps.

"We do not currently know the full extent of everything this can do, nor what its intent is, so extreme caution should be exercised until a complete way to remove any symptoms is found," the fracturizer GitHub researchers recommended. "Everything stated here is only what we know — please keep an eye on communication from the team on updates if anything critical is found."

About the Author(s)

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like

More Insights