Skip to content

Drag the artwork to explore. Use the arrow keys when it is focused.

Security & ExploitsMinecraft Malware

18M Minecraft Records Allegedly For Sale on Crime Forums

Cybernews analyzed the samples and found usernames, emails, and hashed passwords pulled from only three community servers. The common thread is infostealer malware delivered through fake mods, cracked clients, and shady GitHub repos.

2 min read

The Minecraft ecosystem continues to be a soft target. Players chasing mods, “free” clients, texture packs, or automation tools from random Discord links and YouTube descriptions are downloading malware at scale. The latest alleged dump proves it.

Researchers pulled 1,000-record samples from the listings. They contain Minecraft usernames, email addresses tied to accounts, and password hashes. Only three unique community servers appear across the data. No evidence of a central Mojang compromise.

This is not a Mojang data breach. It is the predictable result of an install-any-.jar culture. If your launcher is pulling random code from GitHub or sketchy “mod menus,” you are the product.

The malware in question often comes from Russian-origin infostealers previously documented harvesting browser data, Discord tokens, and crypto wallets alongside Minecraft credentials. Threat actors then package the loot and sell it in batches on cybercrime forums.

Minecraft has over 200 million monthly players. A meaningful percentage run cracked launchers or install unverified mods. That creates a permanent pipeline of fresh compromised accounts. Forum sellers know the audience exists and price the lists accordingly.

What actually happened here

  • Two separate actors listed Minecraft datasets within days of each other
  • Samples overlap and match prior infostealer leaks
  • Data tied to community servers, not official Microsoft services
  • No evidence of database intrusion at Mojang
  • Primary infection vector remains malicious Minecraft software

The timing lines up with ongoing campaigns that use SEO poisoning and Discord file hosting to push fake Xenon Client-style downloads and other popular cheats. Even after infrastructure takedowns earlier this year, the operators simply switched file hosts and kept going.

Google search results for Xenon Client with malicious fake download sites ranking at the top
Fake Xenon Client sites outranking legitimate sources in search results Source

The Minecraft modding and cheating scene is a malware buffet. Players keep clicking the shiny links.

If you run a server, enable proper authentication and tell your players to stop downloading random jars. If you are a player, stick to the official launcher, CurseForge, and Modrinth. Everything else is rolling the dice with your account, your emails, and whatever wallets you have logged in.

Did you enjoy this story?