If you went looking for unfair edges on public SMP servers this week, you might have handed over your entire machine instead. Cybersecurity analysts flagged a newly registered campaign operating under donutsmpcheats.org, a rogue download portal masquerading as a utility and client hub for the popular DonutSMP hardcore server community.
Rather than offering harmless hacks or client-side utilities, the domain hosted seven distinct Java archive (.jar) payloads mimicking popular clients like LiquidBounce, Meteor, and Wurst. Behind the scenes, each file was weaponized with the SilentNet info-stealer, engineered to exfiltrate session data the second the file landed in a player mods folder.
How the SilentNet Trap Sprung
According to research entries logged by abuse.ch database URLhaus, the campaign spun up in September 2026 before entering aggressive distribution. Threat actors targeted players searching for server-specific advantage packs, bundling stolen brand credibility with names like glazed-addon and krypton-client.
Once loaded by Minecraft Java Edition, SilentNet immediately sweeps the host environment. The payload extracts active session tokens from the default launcher directory, snatches Discord authentication tokens, and pulls stored passwords and cookies out of Chromium and Gecko browsers before beaconing back to its command infrastructure.
While the distribution domain went dark on October 8 after security listings triggered DNS takedowns, the danger for infected players is far from resolved. Because the malware operates independently of the original host site once executed, compromised tokens remain valid until account holders actively invalidate sessions and reset authentication keys across secondary devices.

Source
Source
Source





