Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Yes, the campaign was real—but “1,500+ Minecraft players infected” overstates what researchers established. Check Point Research said more than 1,500 devices may have been compromised after users downloaded malicious Minecraft Java Edition mods and cheat tools from GitHub repositories linked to the Stargazers Ghost Network.
The files impersonated tools including Oringo and Taunahi, then used Java loaders to deliver a .NET information stealer. Reported capabilities included stealing Minecraft, Discord, Telegram, Steam, browser, FileZilla, and cryptocurrency-wallet data, along with screenshots, clipboard contents, files, and system information.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Minecraft | Java & Bedrock Deluxe Collection | Windows Digital Code | $39.99 | Buy on Amazon |
| 2 |
|
Minecraft | Java & Bedrock Ultimate Collection | Windows Digital Code | $49.99 | Buy on Amazon |
| 3 |
|
Minecraft | Standard Edition | XBOX Digital Code | $19.99 | Buy on Amazon |
| 4 |
|
Minecraft | $6.99 | Buy on Amazon |
| 5 |
|
Minecraft - Bedrock Edition PS4 | $42.98 | Buy on Amazon |
The short version for Minecraft players
- Do not treat GitHub stars, forks, comments, or a familiar repository layout as proof that a mod is safe.
- A Minecraft Java mod is executable software. A malicious
.jarcan run with the privileges available to Minecraft. - If you only downloaded a suspicious file, delete it, empty the recycle bin, and run a full security scan.
- If you loaded or launched it, assume credentials and active sessions may be exposed. Change passwords and revoke sessions from a separate, trusted device.
- The reported campaign used GitHub as a distribution channel. The available evidence does not show that Minecraft, Mojang/Microsoft infrastructure, or GitHub’s underlying systems were breached.
What happened?
Check Point detected the activity in March 2025 and publicly reported it in June. Researchers linked the campaign to the Stargazers Ghost Network, described as a distribution-as-a-service operation that uses many GitHub accounts, repositories, forks, stars, and copied projects to make malicious downloads appear credible.
According to the researchers, the campaign involved approximately 500 repositories, including forks or copies, and roughly 700 stars generated by about 70 accounts. Those are researcher-attributed campaign figures—not independent measurements of all GitHub activity.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- DELUXE COLLECTION — Includes Minecraft: Java & Bedrock Edition, three Bedrock add-ons, three exclusive Character Creator items, and 700 Minecoins.
- CREATE YOUR WORLD — Build whatever you imagine in an infinite world that’s unique in every playthrough.
- EXPLORE AND CRAFT — Discover biomes, resources, and mobs, then craft your way through a sandbox world filled with surprises.
- SURVIVE THE ADVENTURE — Face mysterious foes, travel across exciting landscapes, and venture into perilous dimensions.
- PLAY TOGETHER — Play cross-platform with friends in Bedrock Edition on console, mobile, and PC, or join community servers in Java Edition on PC, Mac, and Linux. Online console multiplayer requires a platform-specific subscription (sold separately).
The repositories presented files as Minecraft mods, scripts, macros, cheats, or gameplay-enhancement tools. Reported samples included Forge-style Java archives such as Oringo-1.8.9.jar. A filename alone does not prove that every file with that name is malicious, and the reporting does not establish that every legitimate project or historical release associated with Oringo or Taunahi was compromised.
Check Point’s campaign overview and estimated impact are summarized by The Hacker News and in Check Point’s threat-intelligence summary.
Who was targeted?
The campaign focused on Minecraft Java Edition users, particularly people searching for unofficial cheats, macros, scripts, or performance and gameplay tools.
That distinction matters. The reported first- and second-stage components were Java programs intended to run through the Minecraft Java environment. The sources do not describe this as an attack against Bedrock Edition, console editions, or mobile editions. That does not mean other editions are universally risk-free; it means this specific campaign was reported as targeting Java-based mod users.
How the fake-mod attack chain worked
- Discovery: A player searched for a Minecraft mod, cheat, script, macro, or client.
- Trust-building: The player found a GitHub repository made to look popular or legitimate through stars, forks, copied projects, and multiple accounts.
- Download: The player downloaded a Java archive, often a
.jarpresented as a mod. - Installation: The file was placed in Minecraft’s
modsdirectory or otherwise loaded by the game. - Execution: Minecraft’s Java mod loader executed the archive when the game started.
- Anti-analysis: The initial Java loader reportedly used basic anti-virtual-machine and anti-analysis checks.
- Second stage: The loader retrieved another Java-based component.
- Final payload: That component downloaded and executed a .NET information stealer.
- Collection: The stealer searched for credentials, tokens, wallet data, files, screenshots, clipboard contents, running processes, and system information.
- Exfiltration: Stolen information was sent to attacker-controlled infrastructure, including a Discord webhook among the reported mechanisms.
In other words, calling the incident “Java malware” is incomplete. Java handled the initial loader stages; the final stealer was reported as .NET. A technical description of the staged payload appears in TechSpot’s coverage.
Why GitHub made the downloads look trustworthy
GitHub is familiar to players, developers, and mod communities. Its repository pages also provide visible reputation signals: stars, forks, commit history, issue discussions, release pages, and apparent community activity.
Rank #2
- ULTIMATE COLLECTION — Includes Minecraft: Java & Bedrock Edition, five Bedrock add-ons, five exclusive Character Creator items, and 1000 Minecoins.
- CREATE YOUR WORLD — Build whatever you imagine in an infinite world that’s unique in every playthrough.
- EXPLORE AND CRAFT — Discover biomes, resources, and mobs, then craft your way through a sandbox world filled with surprises.
- SURVIVE THE ADVENTURE — Face mysterious foes, travel across exciting landscapes, and venture into perilous dimensions.
- PLAY TOGETHER — Play cross-platform with friends in Bedrock Edition on console, mobile, and PC, or join community servers in Java Edition on PC, Mac, and Linux. Online console multiplayer requires a platform-specific subscription (sold separately).
Attackers abused those signals. A repository with many stars can feel safer than a random file-hosting page, but popularity is not authenticity. Stars and forks can be generated, copied, or coordinated. A repository may also remain visible in search results or reposted links after its original maintainer, files, or context have changed.
Public source hosting is not the same as security review. A JAR can look like an ordinary mod while containing arbitrary Java code. GitHub’s security-advisory documentation describes vulnerability reporting and database processes; it does not guarantee that every uploaded repository or release is safe.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhat could the malware steal?
Reported capabilities included:
- Minecraft authentication tokens
- Discord tokens
- Telegram-related data
- Browser credentials and sessions
- Steam-related data
- FileZilla credentials
- Cryptocurrency-wallet information
- Local files
- Screenshots
- Clipboard contents
- Running-process information
- External IP address and other system information
These are observed or reported capabilities in analyzed samples. They are not a complete victim-by-victim accounting of which information was successfully stolen from every affected device. A sample’s ability to collect browser cookies, for example, does not prove that every victim had cookies exfiltrated.
The danger therefore extended well beyond Minecraft. The game was the lure and execution environment; the likely value to attackers was access to broader accounts, credentials, wallets, files, and sessions.
What does “1,500+ infected” really mean?
The careful wording is:
Check Point estimated that more than 1,500 devices may have been infected.
That is not the same as saying exactly 1,500 individual players were confirmed infected. The estimate may reflect devices, telemetry, campaign reach, or inferred infections. It should not automatically be converted into a count of people, households, Minecraft accounts, or confirmed data-theft victims.
Recommended Free Tools
Rank #3
- CREATE YOUR WORLD — Build whatever you imagine in an infinite world that is unique in every playthrough.
- EXPLORE AND CRAFT — Discover biomes, resources, and mobs, then craft your way through a sandbox world full of surprises.
- SURVIVAL ADVENTURES — Face mysterious foes, travel across varied landscapes, and venture into perilous dimensions.
- PLAY TOGETHER — Play solo or join friends in local split-screen and cross-platform play across console, mobile, and PC. Online multiplayer supports up to 8 players.
- COMMUNITY PLAY — Connect with players on community servers, or subscribe to Realms Plus (sold separately) to play with up to 10 friends on a private server.
The campaign was first detected in March 2025, but that date is not necessarily the date the operation began. The reviewed sources establish the historical campaign and its reported capabilities; they do not establish that the same repositories, payloads, or infrastructure remain active in 2026.
Was Minecraft or GitHub hacked?
Not according to the available reporting. The evidence describes attackers abusing GitHub repositories and accounts to distribute malicious files. It does not establish a breach of GitHub’s core infrastructure.
Likewise, the campaign did not require a compromise of Minecraft’s official code. The malicious software entered through unofficial Java mod downloads and then ran on users’ computers when loaded by Minecraft.
Historical indicators and attribution
Researchers reported a Base64-encoded value that resolved through Pastebin to an attacker-controlled IP address, reported as 147[.]45[.]79[.]104. This is a historical indicator, not proof that the address remains active or malicious in 2026. Readers should not connect to it, download from it, or execute any related sample.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →The campaign was associated with a suspected Russian-speaking threat actor based on Russian-language artifacts and UTC+03:00 commit timestamps. That is circumstantial assessment, not definitive attribution to a named person or organization.
The report also said an example Java loader was undetected by antivirus engines at the time of analysis. That was a sample-specific, time-limited observation—not proof that antivirus software universally failed or that the sample remains undetected.
Rank #4
- Skins! We have biome settlers, city folk, town folk, and more!
- The Nether and all its inhabitants. Fight Ghasts and make friends with Pigmen
- Cross platform play for up to five players between Pocket Edition and Windows 10
- Revamped touch controls, controller support, and a controller mapping screen
- Enhanced Weather effects! Accumulating snow and more
What to do if you downloaded a suspicious mod
If you downloaded it but did not run it
- Do not open the JAR for inspection on your normal computer.
- Delete the downloaded file and empty the recycle bin.
- Run a full scan with your operating system’s security software.
- Check browser downloads and the Minecraft
modsdirectory for unfamiliar files. - If there is any chance Minecraft loaded the file, follow the executed-file procedure below.
Deletion alone does not prove the computer is clean. A staged payload may already have executed if the file was launched or loaded.
If Minecraft loaded or you launched it
- Disconnect the computer from the internet while preserving evidence if an investigation is needed.
- Using a separate, trusted device, change passwords for your Microsoft account, email, Discord, Telegram, Steam, cryptocurrency services, and any account whose credentials were stored in a browser.
- Revoke active sessions and tokens wherever the service provides that option.
- Enable multifactor authentication.
- Run an offline or boot-time security scan.
- Remove suspicious mods, launchers, and installers.
- Review browser extensions, startup items, scheduled tasks, and recently created files.
- If cryptocurrency was handled on the computer, assume wallet credentials or seed material may be exposed and move assets to a clean wallet.
- For a high-confidence compromise, back up only personal documents and reinstall the operating system from trusted media.
Changing only the Minecraft password is not enough if browser credentials, Discord tokens, email access, or wallet data may also have been exposed. Password changes should be performed from a clean device, and changing a password does not necessarily revoke already-stolen cookies or tokens.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Optional scanning tools
Windows users can begin with Microsoft Defender, the built-in security baseline. A second-opinion scanner such as Malwarebytes or ESET Online Scanner may also be useful. These tools are optional; purchasing security software cannot undo credentials or tokens that were already stolen.
VirusTotal can help compare file or URL detections, but uploading a suspicious file may disclose it to a third-party analysis service. Do not upload private documents or sensitive binaries, and do not treat a clean result as proof that a file is safe.
How to install Minecraft mods more safely
- Prefer established mod platforms and the developer’s verified distribution channels.
- Confirm that the official website, source repository, release page, and download page agree with one another.
- Be especially cautious with “cracked,” “free premium,” cheat, macro, bypass, or unauthorized-client downloads.
- Never treat stars, forks, screenshots, or comments as proof of authenticity.
- Review release history, maintainers, signatures, hashes, and credible community warnings where available.
- Keep separate browser profiles or accounts for sensitive activity when practical.
- Use a non-administrator account for routine gaming.
- Keep Windows, your browser, Java runtime, and security software updated.
- Never disable security software merely to run a mod.
Established platforms can reduce risk, but neither GitHub nor any mod platform guarantees that every uploaded file is safe.
This was not the 2023 Fractureiser incident
Minecraft users may confuse this campaign with Fractureiser, but they were separate incidents.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsBest Value
- Play and share with friends on console, mobile and Windows 10
- discover community creations in the new in-game store
- access new mini games and game modes through servers
| Issue | 2025 GitHub campaign | 2023 Fractureiser |
|---|---|---|
| Reported distribution | Malicious GitHub repositories associated with the Stargazers Ghost Network | Infected mods distributed through CurseForge and BukkitDev |
| Reported lure | Fake Oringo, Taunahi, scripts, macros, and cheats | Compromised Minecraft mod ecosystem files |
| Technical chain | Java loader, second Java stage, then .NET stealer | Separate multi-stage Java malware investigation |
| Indicators | Use campaign-specific indicators only | Do not reuse Fractureiser indicators for this campaign |
See the Fractureiser investigation repository and its public FAQ for the earlier incident.
The expert takeaway
A Minecraft mod is not merely a data file. In Java Edition, it is executable software. That makes the download source, maintainer identity, release history, and file integrity important security questions—not just community or compatibility questions.
The larger lesson is that a trusted platform’s reputation signals can be manufactured. GitHub stars and forks may make a malicious repository look established, while the downloaded JAR can target every valuable account on the computer. Treat repository popularity as one clue, never as a security guarantee.
Frequently Asked Questions
Were exactly 1,500 Minecraft players confirmed infected?
No. Check Point estimated that more than 1,500 devices may have been infected. The available reporting does not establish exactly how many people, accounts, or victims were confirmed.
Does this mean every Oringo or Taunahi file is malicious?
No. The campaign reportedly used those names to impersonate tools. That does not prove that every legitimate project or release using either name was compromised.
Can Bedrock Edition players be affected by this specific campaign?
The reported campaign targeted Minecraft Java Edition and used Java archives that required the Java runtime. The sources do not describe it as an attack against Bedrock, console, or mobile editions.
Is this the same as Fractureiser?
No. Fractureiser was a separate 2023 incident involving infected mods distributed through CurseForge and BukkitDev. This campaign involved malicious GitHub repositories and fake Oringo- and Taunahi-related downloads.
The Bottom Line
Bottom line: The reported campaign was a real credential-stealing operation aimed at Minecraft Java Edition users, but the precise claim is that more than 1,500 devices may have been infected—not that 1,500 players were definitively confirmed. If you loaded an unofficial JAR, treat the computer and its stored accounts as potentially compromised: scan or reinstall the machine, then change passwords and revoke sessions from a clean device.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




