Latest reviews

Avoid this build has a backdoor. The plugin's startup code has been patched to call a hidden class bundled inside the jar's META-INF folder instead of the normal plugin logic. On every server start, it decodes an obfuscated URL, checks a Telegram channel page for a download link (or IP), pulls down a jar with no integrity check beyond confirming it has a plugin.yml, renames it to look like a normal library plugin (LibAPI/ServerLibs), and silently loads it into your server then deletes the evidence. That gives whoever controls that Telegram channel remote code execution on your server, on demand, indefinitely. If you already ran this, check your plugins folder for LibAPI or ServerLibs and rotate any credentials the server had access to.
该资源捆绑植入`xmrig`挖矿病毒,解压后在插件目录生成恶意可执行程序。木马会偷跑占用全部 CPU 算力挖矿,造成服务器卡顿、硬件超负荷损耗,严重危害主机安全。下载后险些造成服务器中招,恶意带毒行为极其恶劣,强烈建议所有人避雷,切勿下载该资源。
This is malware, don't even try to install it on server, it infects other .jars
Top