Minecraft Mods Used to Spread Malware: How Stargazers Fake GitHub Mods Stole Passwords and Tokens

A newly uncovered cyber campaign by the Stargazers Ghost Network has targeted thousands of Minecraft players worldwide by distributing malicious mods through GitHub. Disguised as legitimate cheats and tools like Skyblock Extras and Polar Client, these mods deploy a multi-stage malware infection chain designed to steal sensitive data. Once installed, they execute a Java-based infostealer that captures Minecraft session tokens, Discord and Telegram credentials, and even loads a .NET-based stealer named "44 CALIBER" to exfiltrate browser passwords, VPN logins, cryptocurrency wallets, and more. With over 500 malicious GitHub repositories and thousands of views, this attack showcases how popular gaming ecosystems like Minecraft are being exploited for data theft. Security experts urge players to stick to trusted mod platforms, validate GitHub repositories carefully, and use burner accounts to minimize exposure.

Jun 21, 2025 - 12:23
Updated: 8 days ago
105.8k
Minecraft Mods Used to Spread Malware: How Stargazers Fake GitHub Mods Stole Passwords and Tokens

Quick answer: In 2025, Check Point Research found that a criminal "distribution-as-a-service" operation called the Stargazers Ghost Network had published around 500 GitHub repositories offering fake Minecraft mods and cheats. Installing one ran a hidden Java loader that stole Minecraft, Discord and Telegram tokens, then dropped a Windows stealer that took browser passwords, crypto wallets and files. Download mods only from trusted platforms such as Modrinth or CurseForge.

Key takeaways

  • Check Point Research reported about 500 GitHub repositories in the Stargazers network posing as Minecraft mods and cheats in 2025.
  • Download mods only from Modrinth or CurseForge, and be suspicious of a repository because it has many stars, since stars can be faked.
  • If you ran a fake mod, change passwords from a clean device and revoke Minecraft, Discord and Telegram tokens, because stolen tokens bypass passwords.

The campaign is a good case study in how gamers, many of them teenagers, are targeted through the things they trust: popular mod names, GitHub and star counts. Here is what happened, how to tell if you were affected, and what to do about it.

What was the Stargazers Minecraft malware campaign?

It was a malware campaign that disguised information stealers as Minecraft mods and cheat clients. Check Point Research published its findings in June 2025. The key facts from the Check Point Research report and contemporary coverage:

  • Who: the Stargazers Ghost Network, an operation that runs networks of fake GitHub accounts and repositories to distribute other criminals' malware.
  • Scale: roughly 500 GitHub repositories, boosted with around 700 fake stars from about 70 accounts so they looked popular.
  • Bait: names of real or well-known Minecraft mods and cheat tools, including Skyblock Extras, Polar Client, FunnyMap, Oringo and Taunahi.
  • Victims: mainly Windows players of Minecraft Java Edition who download mods outside trusted platforms.
  • Detection: when discovered, the first-stage Java file was not flagged by any antivirus engine on VirusTotal.
  • Attribution clues: Russian-language comments in the code and commit times in UTC+3, which researchers treated as an indication, not proof, of a Russian-speaking operator.

The same network had earlier been linked to a 2024 campaign using Godot game-engine malware that infected more than 17,000 systems, according to Check Point.

How did the fake mods steal data?

The infection ran in three stages. This high-level view is what defenders and parents need; it is not a recipe.

  1. Fake mod (JAR loader): the player drops the downloaded .jar file into the mods folder and starts the game. The loader runs with the player's permissions and quietly fetches the next stage from an encoded link hosted on Pastebin.
  2. Java stealer: collects Minecraft session tokens and data from the official launcher and third-party launchers such as Lunar, Feather and Essential, plus Discord and Telegram tokens, and sends them to the attacker.
  3. .NET stealer ("44 CALIBER"): a Windows information stealer that grabs saved browser passwords and cookies, crypto wallet files, VPN, Steam and FileZilla data, documents, screenshots, clipboard content and system details. Stolen data was sent out through Discord webhooks.

Session tokens matter because they let an attacker use your account without knowing your password, sometimes bypassing two-factor authentication until the session is revoked.

Why did so many players trust these mods?

  • GitHub looks legitimate. Real developers host real mods there, so a repository feels safer than a random download site.
  • Stars and forks were faked. Popularity signals are easy to buy or automate.
  • Cheat clients are already "grey". People searching for cheats expect odd install steps and antivirus warnings, and are more likely to ignore them.
  • Mods run as code. A Minecraft Java mod is a program with the same access to your files as you have. There is no sandbox.
  • Zero detections at first. A clean VirusTotal result only means "not known yet", not "safe".

This pattern repeats across gaming and developer communities; see our coverage of trojanized GitHub repositories targeting gamers and developers.

How do you know if you installed a malicious mod?

Stealers are designed to be quiet, so look for after-effects rather than obvious symptoms:

  • You are suddenly logged out of Minecraft, Discord or Telegram, or see logins from places you don't recognise.
  • Your Discord account sends messages or links you didn't write.
  • Password-reset or "new sign-in" emails arrive for accounts you didn't touch.
  • Crypto disappears from a wallet on the PC.
  • You downloaded a mod or cheat client from a GitHub link, a YouTube description or a Discord server rather than from a mod platform.

What should you do if you think you were infected?

Act from a different, clean device first, because the infected PC may still be sending data.

  1. Disconnect the infected PC from the internet.
  2. Secure your Microsoft account (which owns your Minecraft licence): change the password and sign out of all sessions from the account's security page, then turn on two-factor authentication.
  3. Change your Discord password, which invalidates old tokens, and review Authorised Apps. Do the same for Telegram by ending other active sessions.
  4. Change every password saved in the browser, starting with email, banking and UPI-linked accounts. Use a password manager such as KeePassXC instead of browser-saved passwords from now on.
  5. Move any crypto from wallets on that PC to a new wallet created on a clean device.
  6. Clean the PC: remove the mod, run a full scan with Microsoft Defender and a second-opinion scanner, and ideally reset Windows, because stealers may leave other components behind.

How to download Minecraft mods safely

DoAvoid
Use established platforms such as Modrinth and CurseForge, which review uploads and remove malware when reportedMods and "clients" from GitHub links in YouTube descriptions, Discord servers or forums
Check the author's history and follow links from the mod's official pageTrusting star counts, forks or download numbers alone
Upload unknown files to VirusTotal before running them, knowing a clean result is not a guaranteeCheat clients and "cracked" launchers; they are the most common bait
Keep Microsoft Defender on and Windows updatedTurning antivirus off because "the mod is a false positive"
Use a password manager and 2FA on Microsoft, Discord and emailSaving important passwords in the browser on a gaming PC
Use a separate Windows account (or a separate PC) for gaming and for bankingKeeping crypto wallets on the same account you install mods on

Our guide to using VirusTotal to scan files and URLs explains how to read the results.

What should parents and schools do?

  • Talk to children about where mods come from; "free cheats" are the main lure.
  • Give children a standard (non-admin) Windows account, and keep parents' banking and email on a different account or device.
  • Turn on two-factor authentication for the child's Microsoft and Discord accounts.
  • In school labs, allow game mods only from approved platforms and keep endpoint protection enabled.

Next step

If you have ever installed a mod from a GitHub link, spend ten minutes today checking active sessions on your Microsoft, Discord and email accounts and turning on 2FA. To understand how stealers like this work in general, read our breakdown of how Celestial Stealer takes browser data and crypto.

Related reading

Frequently Asked Questions

It was a 2025 campaign, reported by Check Point Research, in which the Stargazers Ghost Network published around 500 GitHub repositories offering fake Minecraft mods and cheats. The mods installed information stealers that took game, Discord and Telegram tokens, browser passwords and crypto wallets.

Researchers reported fake versions named after Skyblock Extras, Polar Client, FunnyMap, Oringo and Taunahi. The names copied real or popular mods and cheat tools. Malicious copies can reappear under new names, so the download source matters more than the mod name.

The Java stage stole Minecraft session tokens, launcher data from Lunar, Feather and Essential, and Discord and Telegram tokens. A second Windows stealer, 44 CALIBER, took saved browser passwords, crypto wallets, VPN and Steam data, documents, screenshots and clipboard contents.

Yes. Minecraft Java mods are programs that run with the same access to your files as you have, with no sandbox. A malicious mod can steal data or install other malware. Download mods only from trusted platforms such as Modrinth or CurseForge.

Only when the link comes from the mod's official page and a known developer. Stargazers faked stars and forks to make malicious repositories look popular, so star counts and download numbers are not proof that a repository is genuine.

Not always. When discovered, the first-stage Java file in this campaign had zero detections on VirusTotal. Keep Microsoft Defender on and scan unknown files, but treat a clean result as 'not known yet', not as proof that a mod is safe.

From a clean device, change your Microsoft, Discord, Telegram, email and banking passwords, sign out of all sessions and enable two-factor authentication. Move crypto to a new wallet, then disconnect, scan and ideally reset the infected Windows PC.

Minecraft has a huge, young player base used to installing third-party mods, and cheat seekers often ignore warnings. Game, Discord and crypto accounts are easy to resell, and stolen browser passwords give attackers access to email and banking accounts too.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.