October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
VGSources
Blog

More Than 1,500 Devices May Have Been Infected by Fake Minecraft Java Mods on GitHub

A real GitHub malware campaign impersonated Minecraft Java mods and cheats. Check Point estimated that more than 1,500 devices may have been infected, but the evidence does not confirm 1,500 individual players or victims.
Length9 min Posted Quest giverVGSources Team
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes, the campaign was real—but “1,500+ Minecraft players infected” overstates what researchers established. Check Point Research said more than 1,500 devices may have been compromised after users downloaded malicious Minecraft Java Edition mods and cheat tools from GitHub repositories linked to the Stargazers Ghost Network.

The files impersonated tools including Oringo and Taunahi, then used Java loaders to deliver a .NET information stealer. Reported capabilities included stealing Minecraft, Discord, Telegram, Steam, browser, FileZilla, and cryptocurrency-wallet data, along with screenshots, clipboard contents, files, and system information.

The short version for Minecraft players

  • Do not treat GitHub stars, forks, comments, or a familiar repository layout as proof that a mod is safe.
  • A Minecraft Java mod is executable software. A malicious .jar can run with the privileges available to Minecraft.
  • If you only downloaded a suspicious file, delete it, empty the recycle bin, and run a full security scan.
  • If you loaded or launched it, assume credentials and active sessions may be exposed. Change passwords and revoke sessions from a separate, trusted device.
  • The reported campaign used GitHub as a distribution channel. The available evidence does not show that Minecraft, Mojang/Microsoft infrastructure, or GitHub’s underlying systems were breached.

What happened?

Check Point detected the activity in March 2025 and publicly reported it in June. Researchers linked the campaign to the Stargazers Ghost Network, described as a distribution-as-a-service operation that uses many GitHub accounts, repositories, forks, stars, and copied projects to make malicious downloads appear credible.

According to the researchers, the campaign involved approximately 500 repositories, including forks or copies, and roughly 700 stars generated by about 70 accounts. Those are researcher-attributed campaign figures—not independent measurements of all GitHub activity.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Minecraft | Java & Bedrock Deluxe Collection | Windows Digital Code
  • DELUXE COLLECTION — Includes Minecraft: Java & Bedrock Edition, three Bedrock add-ons, three exclusive Character Creator items, and 700 Minecoins.
  • CREATE YOUR WORLD — Build whatever you imagine in an infinite world that’s unique in every playthrough.
  • EXPLORE AND CRAFT — Discover biomes, resources, and mobs, then craft your way through a sandbox world filled with surprises.
  • SURVIVE THE ADVENTURE — Face mysterious foes, travel across exciting landscapes, and venture into perilous dimensions.
  • PLAY TOGETHER — Play cross-platform with friends in Bedrock Edition on console, mobile, and PC, or join community servers in Java Edition on PC, Mac, and Linux. Online console multiplayer requires a platform-specific subscription (sold separately).

The repositories presented files as Minecraft mods, scripts, macros, cheats, or gameplay-enhancement tools. Reported samples included Forge-style Java archives such as Oringo-1.8.9.jar. A filename alone does not prove that every file with that name is malicious, and the reporting does not establish that every legitimate project or historical release associated with Oringo or Taunahi was compromised.

Check Point’s campaign overview and estimated impact are summarized by The Hacker News and in Check Point’s threat-intelligence summary.

Who was targeted?

The campaign focused on Minecraft Java Edition users, particularly people searching for unofficial cheats, macros, scripts, or performance and gameplay tools.

That distinction matters. The reported first- and second-stage components were Java programs intended to run through the Minecraft Java environment. The sources do not describe this as an attack against Bedrock Edition, console editions, or mobile editions. That does not mean other editions are universally risk-free; it means this specific campaign was reported as targeting Java-based mod users.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the fake-mod attack chain worked

  1. Discovery: A player searched for a Minecraft mod, cheat, script, macro, or client.
  2. Trust-building: The player found a GitHub repository made to look popular or legitimate through stars, forks, copied projects, and multiple accounts.
  3. Download: The player downloaded a Java archive, often a .jar presented as a mod.
  4. Installation: The file was placed in Minecraft’s mods directory or otherwise loaded by the game.
  5. Execution: Minecraft’s Java mod loader executed the archive when the game started.
  6. Anti-analysis: The initial Java loader reportedly used basic anti-virtual-machine and anti-analysis checks.
  7. Second stage: The loader retrieved another Java-based component.
  8. Final payload: That component downloaded and executed a .NET information stealer.
  9. Collection: The stealer searched for credentials, tokens, wallet data, files, screenshots, clipboard contents, running processes, and system information.
  10. Exfiltration: Stolen information was sent to attacker-controlled infrastructure, including a Discord webhook among the reported mechanisms.

In other words, calling the incident “Java malware” is incomplete. Java handled the initial loader stages; the final stealer was reported as .NET. A technical description of the staged payload appears in TechSpot’s coverage.

Why GitHub made the downloads look trustworthy

GitHub is familiar to players, developers, and mod communities. Its repository pages also provide visible reputation signals: stars, forks, commit history, issue discussions, release pages, and apparent community activity.

Rank #2
Minecraft | Java & Bedrock Ultimate Collection | Windows Digital Code
  • ULTIMATE COLLECTION — Includes Minecraft: Java & Bedrock Edition, five Bedrock add-ons, five exclusive Character Creator items, and 1000 Minecoins.
  • CREATE YOUR WORLD — Build whatever you imagine in an infinite world that’s unique in every playthrough.
  • EXPLORE AND CRAFT — Discover biomes, resources, and mobs, then craft your way through a sandbox world filled with surprises.
  • SURVIVE THE ADVENTURE — Face mysterious foes, travel across exciting landscapes, and venture into perilous dimensions.
  • PLAY TOGETHER — Play cross-platform with friends in Bedrock Edition on console, mobile, and PC, or join community servers in Java Edition on PC, Mac, and Linux. Online console multiplayer requires a platform-specific subscription (sold separately).

Attackers abused those signals. A repository with many stars can feel safer than a random file-hosting page, but popularity is not authenticity. Stars and forks can be generated, copied, or coordinated. A repository may also remain visible in search results or reposted links after its original maintainer, files, or context have changed.

Public source hosting is not the same as security review. A JAR can look like an ordinary mod while containing arbitrary Java code. GitHub’s security-advisory documentation describes vulnerability reporting and database processes; it does not guarantee that every uploaded repository or release is safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What could the malware steal?

Reported capabilities included:

  • Minecraft authentication tokens
  • Discord tokens
  • Telegram-related data
  • Browser credentials and sessions
  • Steam-related data
  • FileZilla credentials
  • Cryptocurrency-wallet information
  • Local files
  • Screenshots
  • Clipboard contents
  • Running-process information
  • External IP address and other system information

These are observed or reported capabilities in analyzed samples. They are not a complete victim-by-victim accounting of which information was successfully stolen from every affected device. A sample’s ability to collect browser cookies, for example, does not prove that every victim had cookies exfiltrated.

The danger therefore extended well beyond Minecraft. The game was the lure and execution environment; the likely value to attackers was access to broader accounts, credentials, wallets, files, and sessions.

What does “1,500+ infected” really mean?

The careful wording is:

Check Point estimated that more than 1,500 devices may have been infected.

That is not the same as saying exactly 1,500 individual players were confirmed infected. The estimate may reflect devices, telemetry, campaign reach, or inferred infections. It should not automatically be converted into a count of people, households, Minecraft accounts, or confirmed data-theft victims.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Minecraft | Standard Edition | XBOX Digital Code
  • CREATE YOUR WORLD — Build whatever you imagine in an infinite world that is unique in every playthrough.
  • EXPLORE AND CRAFT — Discover biomes, resources, and mobs, then craft your way through a sandbox world full of surprises.
  • SURVIVAL ADVENTURES — Face mysterious foes, travel across varied landscapes, and venture into perilous dimensions.
  • PLAY TOGETHER — Play solo or join friends in local split-screen and cross-platform play across console, mobile, and PC. Online multiplayer supports up to 8 players.
  • COMMUNITY PLAY — Connect with players on community servers, or subscribe to Realms Plus (sold separately) to play with up to 10 friends on a private server.

The campaign was first detected in March 2025, but that date is not necessarily the date the operation began. The reviewed sources establish the historical campaign and its reported capabilities; they do not establish that the same repositories, payloads, or infrastructure remain active in 2026.

Was Minecraft or GitHub hacked?

Not according to the available reporting. The evidence describes attackers abusing GitHub repositories and accounts to distribute malicious files. It does not establish a breach of GitHub’s core infrastructure.

Likewise, the campaign did not require a compromise of Minecraft’s official code. The malicious software entered through unofficial Java mod downloads and then ran on users’ computers when loaded by Minecraft.

Historical indicators and attribution

Researchers reported a Base64-encoded value that resolved through Pastebin to an attacker-controlled IP address, reported as 147[.]45[.]79[.]104. This is a historical indicator, not proof that the address remains active or malicious in 2026. Readers should not connect to it, download from it, or execute any related sample.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The campaign was associated with a suspected Russian-speaking threat actor based on Russian-language artifacts and UTC+03:00 commit timestamps. That is circumstantial assessment, not definitive attribution to a named person or organization.

The report also said an example Java loader was undetected by antivirus engines at the time of analysis. That was a sample-specific, time-limited observation—not proof that antivirus software universally failed or that the sample remains undetected.

Rank #4
Minecraft
  • Skins! We have biome settlers, city folk, town folk, and more!
  • The Nether and all its inhabitants. Fight Ghasts and make friends with Pigmen
  • Cross platform play for up to five players between Pocket Edition and Windows 10
  • Revamped touch controls, controller support, and a controller mapping screen
  • Enhanced Weather effects! Accumulating snow and more

What to do if you downloaded a suspicious mod

If you downloaded it but did not run it

  1. Do not open the JAR for inspection on your normal computer.
  2. Delete the downloaded file and empty the recycle bin.
  3. Run a full scan with your operating system’s security software.
  4. Check browser downloads and the Minecraft mods directory for unfamiliar files.
  5. If there is any chance Minecraft loaded the file, follow the executed-file procedure below.

Deletion alone does not prove the computer is clean. A staged payload may already have executed if the file was launched or loaded.

If Minecraft loaded or you launched it

  1. Disconnect the computer from the internet while preserving evidence if an investigation is needed.
  2. Using a separate, trusted device, change passwords for your Microsoft account, email, Discord, Telegram, Steam, cryptocurrency services, and any account whose credentials were stored in a browser.
  3. Revoke active sessions and tokens wherever the service provides that option.
  4. Enable multifactor authentication.
  5. Run an offline or boot-time security scan.
  6. Remove suspicious mods, launchers, and installers.
  7. Review browser extensions, startup items, scheduled tasks, and recently created files.
  8. If cryptocurrency was handled on the computer, assume wallet credentials or seed material may be exposed and move assets to a clean wallet.
  9. For a high-confidence compromise, back up only personal documents and reinstall the operating system from trusted media.

Changing only the Minecraft password is not enough if browser credentials, Discord tokens, email access, or wallet data may also have been exposed. Password changes should be performed from a clean device, and changing a password does not necessarily revoke already-stolen cookies or tokens.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Optional scanning tools

Windows users can begin with Microsoft Defender, the built-in security baseline. A second-opinion scanner such as Malwarebytes or ESET Online Scanner may also be useful. These tools are optional; purchasing security software cannot undo credentials or tokens that were already stolen.

VirusTotal can help compare file or URL detections, but uploading a suspicious file may disclose it to a third-party analysis service. Do not upload private documents or sensitive binaries, and do not treat a clean result as proof that a file is safe.

How to install Minecraft mods more safely

  • Prefer established mod platforms and the developer’s verified distribution channels.
  • Confirm that the official website, source repository, release page, and download page agree with one another.
  • Be especially cautious with “cracked,” “free premium,” cheat, macro, bypass, or unauthorized-client downloads.
  • Never treat stars, forks, screenshots, or comments as proof of authenticity.
  • Review release history, maintainers, signatures, hashes, and credible community warnings where available.
  • Keep separate browser profiles or accounts for sensitive activity when practical.
  • Use a non-administrator account for routine gaming.
  • Keep Windows, your browser, Java runtime, and security software updated.
  • Never disable security software merely to run a mod.

Established platforms can reduce risk, but neither GitHub nor any mod platform guarantees that every uploaded file is safe.

This was not the 2023 Fractureiser incident

Minecraft users may confuse this campaign with Fractureiser, but they were separate incidents.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Minecraft - Bedrock Edition PS4
  • Play and share with friends on console, mobile and Windows 10
  • discover community creations in the new in-game store
  • access new mini games and game modes through servers
Issue 2025 GitHub campaign 2023 Fractureiser
Reported distribution Malicious GitHub repositories associated with the Stargazers Ghost Network Infected mods distributed through CurseForge and BukkitDev
Reported lure Fake Oringo, Taunahi, scripts, macros, and cheats Compromised Minecraft mod ecosystem files
Technical chain Java loader, second Java stage, then .NET stealer Separate multi-stage Java malware investigation
Indicators Use campaign-specific indicators only Do not reuse Fractureiser indicators for this campaign

See the Fractureiser investigation repository and its public FAQ for the earlier incident.

The expert takeaway

A Minecraft mod is not merely a data file. In Java Edition, it is executable software. That makes the download source, maintainer identity, release history, and file integrity important security questions—not just community or compatibility questions.

The larger lesson is that a trusted platform’s reputation signals can be manufactured. GitHub stars and forks may make a malicious repository look established, while the downloaded JAR can target every valuable account on the computer. Treat repository popularity as one clue, never as a security guarantee.

Frequently Asked Questions

Were exactly 1,500 Minecraft players confirmed infected?

No. Check Point estimated that more than 1,500 devices may have been infected. The available reporting does not establish exactly how many people, accounts, or victims were confirmed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does this mean every Oringo or Taunahi file is malicious?

No. The campaign reportedly used those names to impersonate tools. That does not prove that every legitimate project or release using either name was compromised.

Can Bedrock Edition players be affected by this specific campaign?

The reported campaign targeted Minecraft Java Edition and used Java archives that required the Java runtime. The sources do not describe it as an attack against Bedrock, console, or mobile editions.

Is this the same as Fractureiser?

No. Fractureiser was a separate 2023 incident involving infected mods distributed through CurseForge and BukkitDev. This campaign involved malicious GitHub repositories and fake Oringo- and Taunahi-related downloads.

The Bottom Line

Bottom line: The reported campaign was a real credential-stealing operation aimed at Minecraft Java Edition users, but the precise claim is that more than 1,500 devices may have been infected—not that 1,500 players were definitively confirmed. If you loaded an unofficial JAR, treat the computer and its stored accounts as potentially compromised: scan or reinstall the machine, then change passwords and revoke sessions from a clean device.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 4
Minecraft
Minecraft
Skins! We have biome settlers, city folk, town folk, and more!; The Nether and all its inhabitants. Fight Ghasts and make friends with Pigmen
$6.99
Bestseller No. 5
Minecraft - Bedrock Edition PS4
Minecraft - Bedrock Edition PS4
Play and share with friends on console, mobile and Windows 10; discover community creations in the new in-game store
$42.98

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More quests from Patch Notes

  1. How To Create Custom Stickers & Shoutouts In Monster Hunter WildsMonster Hunter WildsBlog20min
  2. How to Get XL Gogoat in Pokemon Legends Z-A (An Extra-Large Gogoat)Pokemon Legends Z-ABlog20min
  3. How to Get Rotting Lightbringer in Diablo 4Diablo 4Blog17min
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.