Avoid this build has a backdoor. The plugin's startup code has been patched to call a hidden class bundled inside the jar's META-INF folder instead of the normal plugin logic. On every server start, it decodes an obfuscated URL, checks a Telegram channel page for a download link (or IP), pulls down a jar with no integrity check beyond confirming it has a plugin.yml, renames it to look like a normal library plugin (LibAPI/ServerLibs), and silently loads it into your server then deletes the evidence. That gives whoever controls that Telegram channel remote code execution on your server, on demand, indefinitely. If you already ran this, check your plugins folder for LibAPI or ServerLibs and rotate any credentials the server had access to.