<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="https://v1sta.xyz/wp-content/plugins/pretty-rss-feeds/xslt/pretty-feed.xsl" type="text/xsl" media="screen" ?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/">

<channel>
	<title>2023年6月22日 &#8211; 景の域</title>
	<atom:link href="https://v1sta.xyz/2023/06/22/feed/" rel="self" type="application/rss+xml" />
	<link>https://v1sta.xyz</link>
	<description>远景的幻想空间</description>
	<lastBuildDate>Thu, 22 Jun 2023 05:28:34 +0000</lastBuildDate>
	<language>zh-Hans</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://v1sta.xyz/wp-content/uploads/2026/03/V1sta-Orb-Output512-2-60x60.png</url>
	<title>2023年6月22日 &#8211; 景の域</title>
	<link>https://v1sta.xyz</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>防范MC模组的Fracturizer蠕虫病毒</title>
		<link>https://v1sta.xyz/tech/minecraft-fracturizer-virus/</link>
					<comments>https://v1sta.xyz/tech/minecraft-fracturizer-virus/#respond</comments>
		
		<dc:creator><![CDATA[域主 V1STA]]></dc:creator>
		<pubDate>Thu, 22 Jun 2023 04:58:05 +0000</pubDate>
				<category><![CDATA[技术]]></category>
		<category><![CDATA[游戏]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Minecraft]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">https://v1sta.xyz/?p=1414</guid>

					<description><![CDATA[大概是6月高考期间（9号）的时候，爆出了一个消息，说是CurseForge的一些MC模组（Mod）感染了一种名为Fracturizer的病毒，而且能二次传染，通过jar传播，盗取用户的隐私信息……

虽然那个时候我在搬家，没有时间折腾Minecraft，何况我是昨天折腾服务器才知道这则火星新闻的]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">大概是6月高考期间（9号）的时候，爆出了一个消息，说是CurseForge的一些MC模组（Mod）感染了一种名为Fracturizer的病毒，而且能二次传染，通过jar传播，盗取用户的隐私信息……</p>



<p class="wp-block-paragraph">虽然那个时候我在搬家，没有时间折腾Minecraft，何况我是昨天折腾服务器才知道这则火星新闻的</p>



<p class="wp-block-paragraph">经过调查以后，所幸也只是一些“排行榜热门”的模组，我玩的基本上是一些小众Mod，没有感染这个病毒。不过还是有必要记录一番。</p>



<span id="more-1414"></span>



<p class="wp-block-paragraph">国内外的各类玩家和安全论坛、资讯门户几乎都报道了这则重要的消息，在此列出一些我搜集到的链接：</p>



<ul class="wp-block-list">
<li><a href="https://support.curseforge.com/en/support/solutions/articles/9000228509-june-2023-infected-mods-detection-tool/">June 2023 &#8211; Infected mods detection tool &#8211; CurseForge</a></li>



<li><a href="https://www.bilibili.com/read/cv24201292">【安全警告】大量 MC Mod、整合包、服务器插件遭到蠕虫病毒投放，请保持警惕！- 哔哩哔哩</a></li>



<li><a href="https://cert.360.cn/warning/detail?id=6486d92ed5b5ed368982ce1b">安全事件周报 2023-06-05 第23周 &#8211; 360CERT</a> <em><sub>臭名昭著的360也报道了此事</sub></em></li>



<li><a href="https://github.com/fractureiser-investigation/fractureiser/blob/main/lang/zh-CN/docs/users.md">模组玩家自查指南（译文） fractureiser-investigation/fractureiser &#8211; GitHub</a></li>



<li><a href="https://github.com/overwolf/jar-infection-scanner" data-type="URL" data-id="https://github.com/overwolf/jar-infection-scanner">overwolf / jar-infection-scanner &#8211; GitHub</a>  <em>适用Win平台的JAR扫描器</em></li>
</ul>



<p class="wp-block-paragraph"><em>域主用了最后一条的JAR扫描器，并没有发现病毒，不过这个扫描器倒是用MFC写的……</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph">据说是CurseForge的数据库被盗，攻击者通过登录知名作者的账号，在CurseForge分发含有病毒的模组等资源，从而进一步传播到国内外的玩家群中（神似马斯克推特被盗发布诈骗链接的乌龙事件）</p>



<p class="wp-block-paragraph">受病毒影响的整合包和Mod包括了Better MC&nbsp;整合包系列、When Dungeons Arise、Sky Villages、DungeonX、Skyblock Core等等，还有一些Bukkit的插件，由于CurseForge不止托管MC模组，还有WOW的插件等其他游戏的资源，也可能受到了感染。</p>



<p class="wp-block-paragraph">这个病毒会在系统中添加自身的运行守恒，窃取各个浏览器和游戏平台、社交网络的账号登录凭据（微软、Steam、Discord、Twitter等，还有加密币的钱包）；自动下载其他的恶意病毒，勒索程序、让整个基于Java虚拟机的资源（包括MC本体）感染病毒；通过局域网联机分发到其他电脑上，使得一个网络下的所有电脑成为DDoS僵尸集群……</p>



<p class="wp-block-paragraph">简直是一个标准的蠕虫病毒行为，就像2017年那会的WannaCry那样。</p>



<p class="wp-block-paragraph">这个病毒不仅影响主流的Windows，还会影响Linux（但没有表明是否为桌面环境），如果这种病毒会在无头Linux搭建的MC服务器发作，危险性可想而知；不过macOS貌似未受影响，可能是默认有GateKeeper的防护机制，除非用黑苹果关掉了强制应用签名保护。</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph">总之算是虚惊一场，也不能不闻窗外事。以后也许还会遇到病毒的信息。</p>



<p class="wp-block-paragraph">然而我还是要排查究竟是哪个Mod不兼容OptiFine导致进不去世界……模组服是真折腾</p>

<p><a href="https://v1sta.xyz/tech/minecraft-fracturizer-virus/" rel="nofollow">来源</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://v1sta.xyz/tech/minecraft-fracturizer-virus/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<enclosure url="https://v1sta.xyz/wp-content/uploads/2026/03/V1sta-Orb-Output512-2.png" length="199214" type="image/png"/><media:content url="https://v1sta.xyz/wp-content/uploads/2026/03/V1sta-Orb-Output512-2.png" width="512" height="512" medium="image" type="image/png"/>	</item>
	</channel>
</rss>
