Avoid this build has a backdoor. The plugin's startup code has been patched to call a hidden class bundled inside the jar's META-INF folder instead of the normal plugin logic. On every server start, it decodes an obfuscated URL, checks a Telegram channel page for a download link (or IP), pulls down a jar with no integrity check beyond confirming it has a plugin.yml, renames it to look like a normal library plugin (LibAPI/ServerLibs), and silently loads it into your server then deletes the evidence. That gives whoever controls that Telegram channel remote code execution on your server, on demand, indefinitely. If you already ran this, check your plugins folder for LibAPI or ServerLibs and rotate any credentials the server had access to.
I think you left some info you were supposed to remove, so let's make it public, shall we?
This malware is being spread by this Github user: https://github.com/allamititok123/AxMinecart on his github you can find the "blacklist.txt" and "notme-1.0.jar" file.
Here are some links the malware is trying to reach:
decompiled this cracked jar, contains a payload.zip that tries to execute java code from a Telegram message. do not download plugins from this user they are filled with malicious scripts