Minecraft Mods Used to Spread Malware: How Stargazers Fake GitHub Mods Stole Passwords and Tokens
A newly uncovered cyber campaign by the Stargazers Ghost Network has targeted thousands of Minecraft players worldwide by distributing malicious mods through GitHub. Disguised as legitimate cheats and tools like Skyblock Extras and Polar Client, these mods deploy a multi-stage malware infection chain designed to steal sensitive data. Once installed, they execute a Java-based infostealer that captures Minecraft session tokens, Discord and Telegram credentials, and even loads a .NET-based stealer named "44 CALIBER" to exfiltrate browser passwords, VPN logins, cryptocurrency wallets, and more. With over 500 malicious GitHub repositories and thousands of views, this attack showcases how popular gaming ecosystems like Minecraft are being exploited for data theft. Security experts urge players to stick to trusted mod platforms, validate GitHub repositories carefully, and use burner accounts to minimize exposure.
Quick answer: In 2025, Check Point Research found that a criminal "distribution-as-a-service" operation called the Stargazers Ghost Network had published around 500 GitHub repositories offering fake Minecraft mods and cheats. Installing one ran a hidden Java loader that stole Minecraft, Discord and Telegram tokens, then dropped a Windows stealer that took browser passwords, crypto wallets and files. Download mods only from trusted platforms such as Modrinth or CurseForge.
Key takeaways
- Check Point Research reported about 500 GitHub repositories in the Stargazers network posing as Minecraft mods and cheats in 2025.
- Download mods only from Modrinth or CurseForge, and be suspicious of a repository because it has many stars, since stars can be faked.
- If you ran a fake mod, change passwords from a clean device and revoke Minecraft, Discord and Telegram tokens, because stolen tokens bypass passwords.
The campaign is a good case study in how gamers, many of them teenagers, are targeted through the things they trust: popular mod names, GitHub and star counts. Here is what happened, how to tell if you were affected, and what to do about it.
What was the Stargazers Minecraft malware campaign?
It was a malware campaign that disguised information stealers as Minecraft mods and cheat clients. Check Point Research published its findings in June 2025. The key facts from the Check Point Research report and contemporary coverage:
- Who: the Stargazers Ghost Network, an operation that runs networks of fake GitHub accounts and repositories to distribute other criminals' malware.
- Scale: roughly 500 GitHub repositories, boosted with around 700 fake stars from about 70 accounts so they looked popular.
- Bait: names of real or well-known Minecraft mods and cheat tools, including Skyblock Extras, Polar Client, FunnyMap, Oringo and Taunahi.
- Victims: mainly Windows players of Minecraft Java Edition who download mods outside trusted platforms.
- Detection: when discovered, the first-stage Java file was not flagged by any antivirus engine on VirusTotal.
- Attribution clues: Russian-language comments in the code and commit times in UTC+3, which researchers treated as an indication, not proof, of a Russian-speaking operator.
The same network had earlier been linked to a 2024 campaign using Godot game-engine malware that infected more than 17,000 systems, according to Check Point.
How did the fake mods steal data?
The infection ran in three stages. This high-level view is what defenders and parents need; it is not a recipe.
- Fake mod (JAR loader): the player drops the downloaded
.jarfile into the mods folder and starts the game. The loader runs with the player's permissions and quietly fetches the next stage from an encoded link hosted on Pastebin. - Java stealer: collects Minecraft session tokens and data from the official launcher and third-party launchers such as Lunar, Feather and Essential, plus Discord and Telegram tokens, and sends them to the attacker.
- .NET stealer ("44 CALIBER"): a Windows information stealer that grabs saved browser passwords and cookies, crypto wallet files, VPN, Steam and FileZilla data, documents, screenshots, clipboard content and system details. Stolen data was sent out through Discord webhooks.
Session tokens matter because they let an attacker use your account without knowing your password, sometimes bypassing two-factor authentication until the session is revoked.
Why did so many players trust these mods?
- GitHub looks legitimate. Real developers host real mods there, so a repository feels safer than a random download site.
- Stars and forks were faked. Popularity signals are easy to buy or automate.
- Cheat clients are already "grey". People searching for cheats expect odd install steps and antivirus warnings, and are more likely to ignore them.
- Mods run as code. A Minecraft Java mod is a program with the same access to your files as you have. There is no sandbox.
- Zero detections at first. A clean VirusTotal result only means "not known yet", not "safe".
This pattern repeats across gaming and developer communities; see our coverage of trojanized GitHub repositories targeting gamers and developers.
How do you know if you installed a malicious mod?
Stealers are designed to be quiet, so look for after-effects rather than obvious symptoms:
- You are suddenly logged out of Minecraft, Discord or Telegram, or see logins from places you don't recognise.
- Your Discord account sends messages or links you didn't write.
- Password-reset or "new sign-in" emails arrive for accounts you didn't touch.
- Crypto disappears from a wallet on the PC.
- You downloaded a mod or cheat client from a GitHub link, a YouTube description or a Discord server rather than from a mod platform.
What should you do if you think you were infected?
Act from a different, clean device first, because the infected PC may still be sending data.
- Disconnect the infected PC from the internet.
- Secure your Microsoft account (which owns your Minecraft licence): change the password and sign out of all sessions from the account's security page, then turn on two-factor authentication.
- Change your Discord password, which invalidates old tokens, and review Authorised Apps. Do the same for Telegram by ending other active sessions.
- Change every password saved in the browser, starting with email, banking and UPI-linked accounts. Use a password manager such as KeePassXC instead of browser-saved passwords from now on.
- Move any crypto from wallets on that PC to a new wallet created on a clean device.
- Clean the PC: remove the mod, run a full scan with Microsoft Defender and a second-opinion scanner, and ideally reset Windows, because stealers may leave other components behind.
How to download Minecraft mods safely
| Do | Avoid |
|---|---|
| Use established platforms such as Modrinth and CurseForge, which review uploads and remove malware when reported | Mods and "clients" from GitHub links in YouTube descriptions, Discord servers or forums |
| Check the author's history and follow links from the mod's official page | Trusting star counts, forks or download numbers alone |
| Upload unknown files to VirusTotal before running them, knowing a clean result is not a guarantee | Cheat clients and "cracked" launchers; they are the most common bait |
| Keep Microsoft Defender on and Windows updated | Turning antivirus off because "the mod is a false positive" |
| Use a password manager and 2FA on Microsoft, Discord and email | Saving important passwords in the browser on a gaming PC |
| Use a separate Windows account (or a separate PC) for gaming and for banking | Keeping crypto wallets on the same account you install mods on |
Our guide to using VirusTotal to scan files and URLs explains how to read the results.
What should parents and schools do?
- Talk to children about where mods come from; "free cheats" are the main lure.
- Give children a standard (non-admin) Windows account, and keep parents' banking and email on a different account or device.
- Turn on two-factor authentication for the child's Microsoft and Discord accounts.
- In school labs, allow game mods only from approved platforms and keep endpoint protection enabled.
Next step
If you have ever installed a mod from a GitHub link, spend ten minutes today checking active sessions on your Microsoft, Discord and email accounts and turning on 2FA. To understand how stealers like this work in general, read our breakdown of how Celestial Stealer takes browser data and crypto.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0