Minecraft Mod Platforms CurseForge and Bukkit Compromised, Delivering Malware to Users

In recent security disclosures, popular mod platforms CurseForge and Bukkit have revealed that compromised versions of well-known Minecraft mods containing malware installation tools have been uploaded to their platforms. .

In recent security disclosures, popular mod platforms CurseForge and Bukkit have revealed that compromised versions of well-known Minecraft mods containing malware installation tools have been uploaded to their platforms. Users, particularly those who run mods on the Windows or Linux version of Minecraft, are urged to exercise caution and investigate their installation folders. The full extent of the damage caused by these malicious mods is still being assessed.

According to reports from Bleeping Computer, individual mod developers' accounts on CurseForge and Bukkit were specifically targeted by hackers. Subsequently, the compromised versions of their mods were infected with the Fractureiser spyware. Some of these mods were automatically updated through API systems, with several of them having recorded millions of downloads. Over the past three weeks, at least 25 popular mods, including the widely used Better Minecraft multi-mod package, were found to be infected across both platforms.

Fortunately, the hackers focused on individual mod developers' accounts rather than the distribution platforms themselves, minimizing the potential impact. Nonetheless, it is possible that a significant number of Minecraft players may have inadvertently installed Java-based spyware by updating their mods. To mitigate the risks, scanning tools have been provided to identify potential infections, and affected users are advised to clean their computers, which may require a full operating system reinstallation. Additionally, changing passwords on all connected accounts is strongly recommended, as the malware has the capability to search for sensitive information such as bank account, email, and cryptocurrency logins.

As a precautionary measure, Minecraft players are advised to refrain from downloading mods from CurseForge and Bukkit until further notice. It is crucial to exercise caution when obtaining mods or any software from third-party sources. Vigilance and security best practices should always be employed to safeguard personal information and protect against potential malware threats.

Join our newsletter

Subscribe to our newsletter and never miss out on what's happening in the tech world. It's that simple.
subsc