Malicious Minecraft Mod Steals Telegram Sessions, Platform Reporting Seen as Stalled
Baca dalam 60 detik
- Seorang pengguna Reddit menemukan file .jar dalam modpack Minecraft yang dirancang mencuri data sesi Telegram setelah memeriksanya di sandbox dan decompiler.
- Insiden ini menyingkap celah kepercayaan di komunitas gim daring, di mana ajakan uji coba mod dari orang asing kerap diterima tanpa verifikasi ketat.
- Laporan ke platform game disebut tidak ditindaklanjuti, memicu pertanyaan tentang efektivitas moderasi dan perlindungan data pengguna di ekosistem gim.

A Reddit user claims to have found an info-stealer malware disguised as a Minecraft mod file after receiving an unknown invitation via Discord. The finding surfaced in the r/scams subreddit and highlights the cybersecurity risks lurking in online gaming communities, especially when collaboration invitations come from strangers.
According to the shared account, the incident began with a spontaneous offer to try a custom Minecraft modpack. Instead of opening the file directly, the user inspected it in a sandbox environment and dissected the code with a decompiler. That preventive step revealed one of the .jar files as an active data stealer targeting Telegram session files (tdata).
The user said they collected hashes, logs, and video recordings as evidence, then reported it to the platform. However, they claim the report was not meaningfully followed up and the suspected perpetrator's account was not blocked. This frustration raises questions about how seriously platforms handle threats that do not directly target their own assets.
Mods and modpacks are indeed a routine part of the Minecraft experience. Sharing files, custom servers, and community test sessions are commonplace. This makes malicious files packaged as ordinary content potentially spread widely without being noticed. What is exploited is not only technical gaps, but also the trust among community members accustomed to collaborating and joining voice calls with people who appear to share the same interests.
"This is not an isolated case or a single scammer โ there are many people running similar campaigns right now, and reporting them yields no results," the user wrote.
Discussion in the thread also highlighted the vulnerability of young users. One commenter argued that games identified with children are easy targets because their players lack adequate security literacy. However, another commenter disputed the assumption that only children are vulnerable. They emphasized that Minecraft and Roblox are designed for all ages, and many adults are also less cautious about this kind of scam tactic.
One netizen suggested mitigation steps, including changing account settings before and after the incident. They also recommended reporting to Telegram, not just to the game platform, on the grounds that Telegram is the party whose assets were stolen and therefore has a greater incentive to investigate. According to them, game platforms have limited reason to act against a thief who did not touch their accounts.
For Indonesia, this case is relevant given the large base of online game players, including Minecraft and Roblox, as well as the high penetration of Telegram as a messaging app. Awareness of the security of files downloaded from unofficial sources remains low. Users in the country need to be wary of invitations to test mods from strangers, especially if they involve downloading executable .jar files. Hash verification, antivirus scanning, and the use of sandboxes are becoming increasingly important steps.
This incident also highlights the need for an active role by platforms in following up on user reports. When reports are not processed, perpetrators can continue operating and victims increase. Regulators in Indonesia, such as the Ministry of Communication and Informatics, have a mandate to push platforms to be more responsive to cybersecurity complaints. However, without consistent pressure, moderation of harmful content in gaming spaces may remain a gap that is difficult to close.
Going forward, the question is how far game platforms and messaging apps will share responsibility in handling cross-service data theft. Will they form an integrated reporting mechanism, or will they instead pass responsibility back and forth until victims keep falling? Without improvement, the trust that forms the foundation of gaming communities will instead become the easiest weapon for cybercriminals to exploit.



