Drag the artwork to explore. Use the arrow keys when it is focused.

Security & ExploitsMinecraft Malware

DonutSMP Cheats Domain Caught Weaponizing SilentNet Stealer

A malicious site posing as a DonutSMP utility hub dropped trojanized cheat jars loaded with SilentNet malware, harvesting session tokens and browser credentials before burning its DNS.

2 min read

If you went looking for unfair edges on public SMP servers this week, you might have handed over your entire machine instead. Cybersecurity analysts flagged a newly registered campaign operating under donutsmpcheats.org, a rogue download portal masquerading as a utility and client hub for the popular DonutSMP hardcore server community.

Rather than offering harmless hacks or client-side utilities, the domain hosted seven distinct Java archive (.jar) payloads mimicking popular clients like LiquidBounce, Meteor, and Wurst. Behind the scenes, each file was weaponized with the SilentNet info-stealer, engineered to exfiltrate session data the second the file landed in a player mods folder.

The golden rule of Java modding remains unbroken: a Minecraft .jar is not a passive data asset. It is an un-sandboxed executable program with the exact same OS-level privileges as the user who launched it.

How the SilentNet Trap Sprung

According to research entries logged by abuse.ch database URLhaus, the campaign spun up in September 2026 before entering aggressive distribution. Threat actors targeted players searching for server-specific advantage packs, bundling stolen brand credibility with names like glazed-addon and krypton-client.

Once loaded by Minecraft Java Edition, SilentNet immediately sweeps the host environment. The payload extracts active session tokens from the default launcher directory, snatches Discord authentication tokens, and pulls stored passwords and cookies out of Chromium and Gecko browsers before beaconing back to its command infrastructure.

While the distribution domain went dark on October 8 after security listings triggered DNS takedowns, the danger for infected players is far from resolved. Because the malware operates independently of the original host site once executed, compromised tokens remain valid until account holders actively invalidate sessions and reset authentication keys across secondary devices.

Editorial comic inspired by: DonutSMP Cheats Domain Caught Weaponizing SilentNet Stealer

Did you enjoy this story?