Skip to content

Drag the artwork to explore. Use the arrow keys when it is focused.

Security & ExploitsMinecraft Malware

Minecraft Modpack Invite Hid Active Telegram Session Stealer

A stranger slid into a player's Discord asking them to test a custom modpack. One sandbox check later they found a .jar designed to steal Telegram tdata sessions. Their full evidence package got ignored and the campaign is still running.

3 min read

Minecraft’s mod scene runs on trust. You see a cool pack someone wants you to test you hop in a Discord call and run the jars. Most of the time it is fine. Sometimes it is not.

According to a detailed post in r/scams a stranger reached out over Discord offering a custom Minecraft modpack test session. The recipient did the smart thing: dropped the files into a sandbox and opened a decompiler instead of double-clicking. What they found was one .jar acting as an active info-stealer aimed squarely at Telegram’s tdata folder.

Session theft like this is nasty because it does not trigger new-device alerts or 2FA prompts. From Telegram’s perspective an already-authenticated session simply starts talking from somewhere else. The poster compiled hashes logs decompiled code and a video walkthrough before reporting the account.

Reporting it went nowhere. The poster says platform support barely looked at the evidence and took no action against the account. They explicitly warned this is not a one-off: multiple people are running the exact same campaign right now and reports keep hitting the same wall.

The story surfaced on The Cool Down yesterday and lines up with the original Reddit thread. It is a textbook example of how Discord invites combined with Minecraft’s enthusiastic modding culture create an easy vector. Players are conditioned to accept random jars from people who sound friendly. One wrong click and your Telegram (and anything linked to it) can be quietly cloned.

Why this keeps working

  • Unsolicited "test my pack" messages exploit the social side of Minecraft content creation
  • Telegram tdata theft bypasses standard login notifications
  • Game platforms see it as a Telegram problem and Telegram sees it as a random .jar problem
  • Evidence packages with video and hashes still do not produce bans in many cases

The poster was careful. Most people are not. That is the point. If you get random Discord invites to test modpacks or join test servers treat every .jar as hostile until proven otherwise. Sandbox it decompile it or just say no. The convenience of quick group play is not worth handing someone your sessions.

Blunt read: Minecraft’s mod ecosystem runs on good faith that platforms refuse to police at scale. Until reporting actually leads to account bans these campaigns will keep cycling through new victims because the cost of getting caught is effectively zero.

If you run into the same tactic document everything and report it to both Discord and Telegram abuse channels. The more noise that is made the harder it becomes for these campaigns to hide in plain sight. In the meantime assume every surprise modpack is trying to take something from you.

Reddit · r/Scams

Got_invited_to_test_a_custom_minecraft_modpack

Original r/scams thread

Post ID: 1wh0uw5

Did you enjoy this story?

Keep reading