CurseForge A.I CyberSecurity Scoring
CurseForge
Company Information
Website:https://www.curseforge.com/
Employees number:15
Number of followers:1,000,000
NAICS:51126
Industry Type:Computer Games
Homepage:curseforge.com
CurseForge Risk Score (AI oriented)
Between 700 and 749
CurseForgeComputer Games
Updated:
07/09/2026
07/09/2026
737/1000
Moderate
Ba
CurseForge Global Score (TPRM)
xxxx
CurseForgeComputer Games
Score locked

CurseForgeModerate
Current Score
737Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
755
Cyber Attack
07 Sep 2026 • CurseForge
Dropbox, CurseForge and Modrinth: Fake Minecraft Mod Drops Myth Stealer RAT to Steal Passwords and Remotely Control PCs
Malicious Minecraft Mod Deploys Myth Stealer 3.2-FIX in Sophisticated Cyberattack
737
MEDIUM-18
CURRINDRO1788769843
Malicious Minecraft Mod Deploys Myth Stealer 3.2-FIX in Sophisticated Cyberattack
A trojanized Minecraft optimization mod, disguised as a companion to the legitimate Lithium performance mod, has been distributing Myth Stealer 3.2-FIX a password-stealing malware with remote-access, surveillance, and victim-harassment capabilities. The malicious archive, tracked as MythStealer.jar, impersonates Lithium Extras 0.15.0+mc1.21.1 by a developer named "soder," leveraging the reputation of CaffeineMC’s open-source Lithium project to appear trustworthy.
The counterfeit mod initially functions as expected, with 12 of its 13 modules performing legitimate optimization tasks. However, the hidden 13th component delays execution for eight seconds before querying ip-api[.]com for the victim’s public IP and country code, collecting the hostname, and downloading a secondary payload from Dropbox. The downloaded executable, DiscordNitroGenerator.exe, is saved to %APPDATA%\Microsoft\Windows\javaw.exe a path designed to evade detection by blending into systems where Java is commonly used for Minecraft.
The first-stage dropper reports infection progress to a Discord webhook and re-downloads the payload if missing or under 50 MB. At the time of discovery, both the Java archive and the 169 MB executable showed zero detections on VirusTotal, likely due to the campaign’s use of a newly created Discord webhook and seemingly legitimate mod functionality.
The malware bundles a private Java runtime, allowing it to execute even on systems without Java installed. Before launching the payload, the loader displays a fake Windows UAC prompt via PowerShell WinForms, tricking users into granting elevated privileges. The stealer then disables Java bytecode verification, enabling the execution of heavily obfuscated malicious code.
Myth Stealer 3.2-FIX is a Java-based remote-access tool (RAT) with 251 classes hidden in a package named complexer/NUL, exploiting the Windows reserved device name NUL to disrupt analysis tools. Its capabilities include:
- Credential theft: Harvests saved usernames, passwords, payment card details (including CVVs), and browser cookies from Chromium and Firefox-based browsers.
- System profiling: Collects hostname, hardware IDs, OS details, and hardware identifiers via WMI queries.
- Data exfiltration: Steals chat logs, browsing history, and local files, which it can ZIP and exfiltrate.
- Remote control: Enables process hollowing, fileless execution, AMSI bypass, ETW patching, and direct manipulation of the victim’s mouse and keyboard.
- Victim harassment: Includes disruptive functions such as screen rotation, cursor replacement, taskbar hiding, fake error messages, and optical-drive control.
The malware communicates with command-and-control (C2) servers via a custom Netty-based TCP protocol, using RSA-OAEP-protected AES-GCM encryption despite lacking TLS. Researchers identified two C2 configurations: the IP 146[.]19[.]191[.]11 and the domain ays[.]gamepazarin[.]com, which mimics the legitimate Turkish game marketplace gamepazari[.]com.
The campaign highlights how threat actors combine functional game modifications, trusted project impersonation, and social engineering to evade detection. Users are advised to download mods only from verified sources such as Modrinth, CurseForge, or official developer repositories. Indicators of compromise (IOCs) include the SHA256 hashes for MythStealer.jar, DiscordNitroGenerator.exe, and client.jar.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
755
JULY 2026
755
JUNE 2026
755
MAY 2026
755
APRIL 2026
755
MARCH 2026
755
FEBRUARY 2026
755
JANUARY 2026
755
DECEMBER 2025
755
NOVEMBER 2025
755
OCTOBER 2025
755
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CurseForge ??
What was CurseForge's A.I Rankiteo Cyber Score in August 2026 ??
What was CurseForge's A.I Rankiteo Cyber Score in July 2026 ??
What was CurseForge's A.I Rankiteo Cyber Score in June 2026 ??
What was CurseForge's A.I Rankiteo Cyber Score in May 2026 ??
What was CurseForge's A.I Rankiteo Cyber Score in April 2026 ??
What was CurseForge's A.I Rankiteo Cyber Score in March 2026 ??
What was CurseForge's A.I Rankiteo Cyber Score in February 2026 ??
What was CurseForge's A.I Rankiteo Cyber Score in January 2026 ??
What was CurseForge's A.I Rankiteo Cyber Score in December 2025 ??
What was CurseForge's A.I Rankiteo Cyber Score in November 2025 ??
What was CurseForge's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on CurseForge's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CurseForge ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CurseForge's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?