That link is weirdly embedding rather than just redirecting or referring to a github page. It doesn't seem malicious, but Firefox at least complained that it violates GitHub's content-security policies on their pages.
https://github.com/fractureiser-investigation/fractureiser seems to be the correct underlying content. I'd also recommend you retitle this to "Minecraft mod users beware", as there exists at least one gamer who does not use Minecraft mods.
It does seem like impressively dangerous malware.
Place your (fake) bets on whether this was caused by ChatGPT or one of its cousins! https://manifold.markets/GarrettBaker/did-a-llm-contribute-significantly
Thank you for heads up!
Could you please clarify for parents like me, who don't fully understand Minecraft's ecosystem and just want their kids to stay safe:
1. If my kids only use Minecraft downloaded from the Microsoft Store, and only ever downloaded content from the in-game marketplace - what's the chance they are affected?
2. Am I right in thinking that "mods" = "something which modifies/extends the executable", while "add-ons"="more declarative content which just interacts with existing APIs, like maps, skins, and configs"?
3. Am I right that "Minecraft from Micosoft Store" + "content from in-game marketplace" would translate to "Bedrock Edition" + "add-ons"?
4. Am I right that the fractureiser affects "Java Edition" + "mods" only?
As someone who played modded minecraft (but I am not the OP, who might have more accurate information and a better understanding)
In short, if your kids are on bedrock, then your computers are probably safe.
The malware is embedded in multiple mods, some of which were added to highly popular modpacks.
Any info on how this happened? This seems like a fairly serious supply chain attack. I have heard of incidents with individual malicious packages on npm or PyPI, but not one where multiple high profile packages in a software repository were infected in a coordinated manner.
Send this to anyone who was playing modded Minecraft on work machines. Or anyone playing modded Minecraft at all, really!