Minecraft Modpack Scam Targeted Telegram Sessions
A malicious .jar file disguised as a game mod has been identified exploiting platform trust to hijack user data.
Updated on Sept. 28, 2026 in Cybersecurity

Live Poll
Do you trust files sent by strangers within online gaming communities?
A Reddit user identified a Discord-based scam involving a malicious Minecraft modpack designed to steal Telegram session data. Despite reporting the incident, the user stated that platform support failed to intervene or ban the malicious account.
Why it matters
This incident highlights how attackers weaponize social trust in gaming communities to deliver info-stealers. The failure of moderation processes to address reported threats creates a critical security gap for users on collaborative platforms.
The malicious file contained an info-stealer designed to target tdata files, which store active session data for Telegram. These files allow attackers to bypass login requirements by hijacking an existing, authenticated user session.
The players
Discord
A communication platform for communities that facilitates file sharing and real-time interaction but faces persistent challenges with malicious link and file distribution.
Telegram
A cross-platform messaging service that relies on local session files to maintain user authentication status.
Minecraft
A widely used creative sandbox game with a massive ecosystem of user-created mods, frequently targeted by actors distributing unauthorized or malicious code.
The details
The user identified the threat by sandboxing—running the code in an isolated, restricted virtual environment—and decompiling the .jar files before execution. By inspecting the code, they found the malware was configured specifically to locate and exfiltrate the Telegram session data that keeps users logged into the messaging app. The scam relies on social engineering, leveraging the expectation within Minecraft communities that members frequently share and test custom mods with one another.
Timeline
September 28, 2026: The report documenting the scam and the failed platform response was published.
The Tech Race
This scam underscores the ongoing struggle to secure decentralized software distribution channels against sophisticated social engineering. While security researchers rely on the 2020 SolarWinds supply chain attack to illustrate the dangers of compromised dependencies, this incident shows how individual users have become the primary vectors for such breaches.
Users should treat all unsolicited files, even those shared in trusted gaming communities, as potential threats to their account security. If an account is suspected of hosting malware, continue to submit reports even if initial moderation support responses appear insufficient.
The takeaway
The primary risk here is session hijacking, which can grant an attacker full access to your messaging accounts without needing your password. Monitor your active sessions in the Telegram app settings and revoke any unrecognized connections to protect your account.
Further reading
For broader trends in digital safety and software supply chain threats, review the latest updates at Cybersecurity.
Source note: This article includes information reported by The Cool Down.
Live Poll
Do you trust files sent by strangers within online gaming communities?







