donutclients.st: a Minecraft mod site whose 30 .jar files URLhaus tags as stealers, and what to do if you ran one on Windows

donutclients.st is a website that offers 30 free Minecraft mods for Fabric, and URLhaus lists all 30 of its .jar files (such as Sodium-26.2.jar and meteor-client-26.2.jar) as malware downloads tagged stealer on 7 October 2026.

A mod is a program that runs inside Java with the same rights as you, so if you put one of these files into your Minecraft mods folder and started the game, treat the Windows PC as compromised: change your passwords from another device, then scan and clean or reset Windows. If you only saw the name in a search result or a log, nothing is proven.

Facts checked October 11, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If a Minecraft mod .jar file downloaded from donutclients.st keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove donutclients.st (Minecraft mod .jar files tagged stealer) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Overview of the 30 URLhaus entries for donutclients.st: all added on 7 October 2026 between 04:41 and 04:55 UTC, all .jar files, all tagged stealer, java and vm, all offline
The 30 URLhaus entries for donutclients.st as we hold them. Our own check was a plain request from our server, with no browser and no download, so this list of reports is the main evidence.

Donutclients.st (Minecraft mod .jar files tagged stealer): summary

TypeA Minecraft mod download site: URLhaus tags all 30 of its .jar files stealer, java and vm
RiskHigh if you put one of its files in your mods folder and started the game: logins, tokens and wallets may be taken. Low if you only saw the name
SymptomsOften none. A mod you did not choose, login alerts, or messages you did not send are the signs to look for
How to get rid of itChange passwords from another device, delete the .jar, run Microsoft Defender Offline, and reset Windows if you are not sure
Our check (11 October 2026)One plain request: the home page answered with status 200. A live page clears nothing; the danger rating comes from URLhaus
Running since / first seenRegistration date unknown; the 30 files were reported on 7 October 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 8 more facts
PlatformWindows mainly; Java mods can run on Mac and Linux too. Phones are not affected
Detection namesNo Microsoft detection name is known for these files, because we did not open them
NameDonutclients.st
Evidence30 write-ups by security sites; details still limited
First seen7 October 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked11 October 2026

Facts checked on 11 October 2026 against the 30 URLhaus entries for donutclients.st held in our database, one plain request from our server, a registration lookup that found no record, Microsoft Learn's Defender Offline page, the FTC's page on hacked accounts and the fractureiser repository page, which we read in full.

The Check Point Research and G Data reports were read only as search summaries in this run, so their details are marked as such. We did not download the files and infected no PC; the removal steps follow Microsoft's page and were not tried on a live infection.

What donutclients.st is, and what we know about it

donutclients.st is not a program on your PC. It is a web address that presents itself as a download page for Minecraft mods, and the abuse.ch project URLhaus lists every one of the 30 .jar files we hold for it as a malware download tagged stealer. We found no public write-up of this one address, so what follows is what URLhaus shows, what our server saw on one plain request, and what security researchers have published about malicious Minecraft mods in general.

  1. 1

    What URLhaus lists

    Thirty file addresses on donutclients.st, all in the top folder of the site and all named like a mod plus the version 26.2 and the ending .jar. They were added on 7 October 2026: 29 of them between 04:41:06 and 04:41:31 UTC and the last one, TotemCounter-26.2.jar, at 04:55 UTC. Every entry has the threat label malware_download and the reporter name wok. When we read our copy of the data, all 30 were marked offline.

  2. 2

    What the tags mean

    jar means a Java archive, the format Minecraft mods use. java names the language. stealer means the reporter believes the file steals data such as passwords and sessions. The fourth tag, vm, appears on every entry, and we do not know what the reporter meant by it. It may refer to the way the file behaved in a test machine, but that is a guess and we do not rely on it.

  3. 3

    What the file names tell you

    Many names copy well known mods or mod menus: Sodium, Lithium, Iris, FerriteCore, Litematica, WorldEdit, Baritone, Xaeros_Minimap, appleskin, Mouse_Tweaks and meteor-client among them. Others look like cheat clients: krypton-client, radium-client, glazed-client, bamboo-client. We are not saying the real projects with those names are harmful. We are saying that the files served from this address under those names are the ones URLhaus lists, and the real projects are published on their own sites.

  4. 4

    What we could not confirm

    We did not download any of the files, so we cannot tell you which stealer family is inside, what it takes, or where it sends the data. The tags are a reporter's label, not a proof, and we have no Microsoft detection name for these files. We also cannot tell whether the site's owner knows about it, whether the site was built to spread malware, or whether someone swapped the files on a real mod page.

Kind of threat
A mod download site whose 30 reported .jar files are tagged stealer, java and vm by URLhaus
Where the files are
hxxps://donutclients[.]st/NAME-26.2.jar, for example hxxps://donutclients[.]st/Sodium-26.2.jar. Plain file names in the root of the site
Domain registered
Unknown. Our registration lookup (RDAP) returned no record for the .st domain on 7 October 2026, so we cannot give a date or a registrar
URLhaus entries
30 file addresses, all added on 7 October 2026 (04:41 to 04:55 UTC); all 30 offline in our copy of the data
Home page
Answered with HTTP 200 on 11 October 2026 behind Cloudflare, with the title DonutClients, 30+ Free DonutSMP Mods for Fabric 26.2
Platform
Windows is the main case. Java mods can also run on Mac and Linux, and we found nothing that limits these files to Windows. Phones are not affected, because Minecraft Java mods do not load there

What donutclients.st (Minecraft mod .jar files tagged stealer) does on an infected PC

What we checked on 11 October 2026, and what we could not

Our check was one plain request from our server: no browser, no clicks, no download. The home page answered, so the site is not simply gone. That clears nothing, because the danger rating comes from what URLhaus reports about the files, not from a home page.

Our check, 11 October 2026

  • The home page answersHTTP status 200, no redirect, served through Cloudflare. The page title reads DonutClients, 30+ Free DonutSMP Mods for Fabric 26.2. The site is therefore live and advertises the same number of mods, 30, as URLhaus lists files.
  • Why that is not a clean resultA plain request cannot run scripts, click a download button or look like a real visitor. A site can show a harmless page to one kind of visitor and a different file to another. Cloudflare in front of a site only hides the real server and says nothing about safety.
  • Notification requestOur request found no mention of a browser notification API. This is one plain visit, so it proves nothing about what a browser would be asked.
  • URLhaus listing30 .jar files tagged stealer, java and vm, added on 7 October 2026. All 30 were offline in our copy of the data, which means the files were not downloadable when URLhaus last checked, not that the danger is over.
  • Downloads and the files themselvesWe did not download any .jar file and did not open it. We cannot tell you what the files contain or whether the ones offered today are the same as the reported ones.

Dangerous: do not download or run files from this site The rating comes from the 30 URLhaus reports and their stealer tag. Our one plain request found a live home page and tells you nothing more. Offline file addresses can come back, change, or be replaced under the same names.

What happened to donutclients.st, as far as the data shows

Everything we hold is from a few days: 30 reports within about 15 minutes on 7 October 2026, and one check of ours four days later. Times are UTC. We have no record of the site before that.

  1. Before 7 October 2026

    Registration date unknown

    Our registration lookup found no record for donutclients.st, so we do not know when the domain was registered or by whom. The .st top level domain belongs to Sao Tome and Principe. That is a fact about the ending, not a sign of anything by itself.

  2. 7 October 2026, 04:41 UTC

    A burst of 29 mod files is reported

    Between 04:41:06 and 04:41:31 the reporter wok adds 29 files in about 25 seconds, from WorldEdit-26.2.jar and ExploitPreventer-26.2.jar to meteor-client-26.2.jar, alycone-client-26.2.jar and radium-client-26.2.jar. All carry the tags jar, java, stealer and vm.

    Overview of the 30 URLhaus entries for donutclients.st with the date, the tags and the status offline
    The 30 URLhaus entries for donutclients.st at a glance: one date, one reporter, the same four tags on every file.
  3. 7 October 2026, 04:55 UTC

    A last file: TotemCounter

    TotemCounter-26.2.jar is added at 04:55:41 with the same four tags. Together with the earlier burst this makes 30 entries. The speed of the reports looks like someone going through the site's whole download list in one pass, which is our reading of the timestamps, not something a report says.

  4. 11 October 2026

    Our check

    Our server asks for the home page once. It answers with status 200 and the title DonutClients, 30+ Free DonutSMP Mods for Fabric 26.2. We do not download files. The 30 entries are still marked offline in our copy of the data.

What the pattern suggests, and what it does not: every file has the same version number, 26.2, which matches the title of the page. That fits a site that built one complete mod pack and put every file under one version label. It does not tell us whether the files were made malicious by the site owner, by someone who broke into the site, or by a copy of the mods that was altered before the site got it.

How a Minecraft mod can steal from a PC

A .jar mod is not a picture or a document. It is a program that Minecraft loads and runs with your Windows rights the moment the game starts. Nothing needs to be clicked in a pop-up. This is how Check Point Research and G Data describe the technique; we did not see the files from donutclients.st ourselves.

Four steps of a malicious mod: a download page offers a free mod, the jar is put in the mods folder, the game starts and runs the hidden code, and the stealer sends data to its owner
The chain of a malicious Minecraft mod in four steps, as researchers describe it. What the files from this site do exactly is not known.
  1. 1

    A page offers a free mod or client

    The lure is a free mod, a cheat client or a pack for a popular server. Check Point Research (June 2025) describes fake Minecraft mods spread through GitHub repositories that posed as cheat tools, run by a service it calls the Stargazers Ghost Network. The page here advertises free mods for a named server, which fits the same kind of lure.

  2. 2

    You put the .jar into the mods folder

    That is what every mod guide tells you to do, so it does not feel risky. On Windows the usual place is the mods folder inside .minecraft under your AppData folder. A malicious file looks just like a good one, and the name can be copied from a real mod.

  3. 3

    Starting the game runs the hidden code

    G Data (March 2026) describes a case where a real AppleSkin mod file was altered: the attacker added a hook into the mod's normal start routine, so the malware runs when Fabric starts the mod, while the mod still works. That is why nothing looks wrong. We note that appleskin-26.2.jar is among the 30 file names, but we do not know that its content matches that case.

  4. 4

    A downloader brings the next stage

    Check Point describes a Java downloader, a second stage in Java that steals launcher and chat tokens, and a final stage written in .NET that steals browser credentials, crypto wallets and VPN profiles. The Java stages only run where Minecraft is installed, which helps them slip past automatic analysis. Whether the donutclients.st files use more than one stage is not known.

  5. 5

    The stolen data is sent away

    The stealer packs what it found and sends it to a server of its owner. The owner then uses the logins, or sells them. You may see nothing at all on screen.

This is not new. In June 2023 the fractureiser investigation team described a virus found in several mods uploaded to CurseForge and BukkitDev, some of which were added to popular modpacks, and said it targeted Windows and Linux. The team's page says its event has ended, with no further activity found in the three months before, and also warns that a copycat is possible. A mod folder has been a target for years.

What donutclients.st (Minecraft mod .jar files tagged stealer) can steal or download

What a Minecraft mod stealer can take from a Windows PC

We do not know what these 30 files take. The list below is what researchers found in comparable Minecraft stealers. Treat it as the set of things worth changing after an infection, not as a statement about this site.

Reported for comparable Minecraft stealers

  • Launcher tokens (Feather, Essential, Lunar)
  • Discord tokens
  • Telegram tokens
  • Saved browser passwords
  • Cryptocurrency wallet data
  • VPN profiles
  • Minecraft account sessions
Sources: Check Point Research on the Stargazers Ghost Network (June 2025). We read this report through a search summary, not in full, and we mark that in the source list.
DataDetailSource
Launcher and chat tokensThe Java stage goes after launcher tokens of Feather, Essential and Lunar, plus Discord and Telegram tokensCheck Point Research, read through a search summary
Browser loginsThe final .NET stage targets browser credentialsCheck Point Research
Crypto and VPNCrypto wallets and VPN profiles are also targets of that stageCheck Point Research
Your gameA token for your game account lets a stranger log in as you; we found no source that says how often this happens, so we call it a risk, not a factOur reading

What this can cost you

Seeing the name of the site or visiting its home page is not what the risks below are about. They apply to a PC where one of the .jar files was put into the mods folder and the game was started.

  • High

    Passwords and accounts

    If the file is a stealer, the logins saved in your browsers can be read. Email comes first, because it resets everything else. Changing a password on the infected PC does not help while the file is still there.

  • High

    Discord, Telegram and launcher sessions

    A stolen token lets a stranger use your account without a password and often without a code. Researchers name these tokens as targets. Servers you moderate and friends you message are at risk too.

  • High

    Crypto

    Wallet data is a named target in comparable stealers. Crypto sent from a stolen wallet cannot be reversed.

  • Medium

    Your Minecraft account and server standing

    Someone logging in as you can get you banned on a server, spend your in game money or steal items. For a name tied to a popular server this is a real loss, even if it is not a bank loss.

  • Medium

    More malware later

    A downloader stage can bring other programs. The first file is often only the door.

  • Low

    Nothing, if you only saw the name

    A name in a log, a block list or a search result is not an infection.

What you may notice, and what you may not

Stealers are built to be quiet. The signs below are possible, none is certain, and many victims notice nothing until an account is used by someone else.

SignWhat it may mean
A mod you did not choose in the mods folderA new or renamed .jar file with a recent date. This is the most direct sign, and it is worth checking even if the game runs fine
Login alerts or password reset emailsSomeone tried or managed to use a stolen login. This follows from how stealers work and is our reading, not a quote
Messages sent from your Discord or TelegramInvites or links you did not send are a common sign of a stolen token
A Windows Security detection after a mod ranLook in Protection history. Detection names for Java stealers vary, and we have no name for these files
An unknown program or scheduled taskSome stealers install something to start again. We do not know if these files do
Nothing at allA quiet game is normal for a hidden hook in a working mod, as G Data describes

How to check the PC for donutclients.st (Minecraft mod .jar files tagged stealer)

Who can meet these files, and how

The people who meet this are players who look for free mods, cheat clients or packs for a server such as the one named in the site's title. Searchers and ad clicks bring them to a download page that looks like a normal mod site.

  1. 1

    You downloaded a mod or client from the site

    This is the case that matters. If a file named like Sodium-26.2.jar or meteor-client-26.2.jar came from this address, you hold a file that URLhaus tags as a stealer. Do not start the game with it.

  2. 2

    A friend or a video sent you the link

    Check Point describes the Minecraft cheat scene as one where malware is passed through repositories and sharing. A link from a friend whose account was already stolen is a common route; we have no data that this happened here.

  3. 3

    You only visited the page

    Visiting a page and not downloading anything is much lower risk. The danger starts when a file is saved and run. Close the tab and, to be safe, clear the downloads folder of anything you did not mean to keep.

  4. 4

    You run a server, a modpack or a mod page of your own

    If you saw donutclients.st in your own files or links, check where it came from. A hacked page, a changed download link or a pack that pulled a file from here would spread it. Replace the link with the mod's official page and change the passwords of your site and host.

Check your PC before you delete anything

The question that matters is whether a .jar from this site ever ran on your PC. If you downloaded one but never started Minecraft with it, you have a file to delete and a lower risk. If you started the game with it in the mods folder, do all the checks below. None of them deletes anything.

While you check, stop using the PC for banking, email, work or crypto, and do the account changes from another device.

  1. 1

    Find the file

    Open File Explorer, type %appdata%\.minecraft\mods in the address bar and press Enter. Sort by Date modified. Look for any .jar you did not install yourself, and open your Downloads folder for files ending in -26.2.jar. Launchers such as Prism, CurseForge or Modrinth may use their own folders; look at the instance folder shown in the launcher. Do not delete yet. Write down the names.

  2. 2

    Disconnect if you started the game with it

    Turn off Wi-Fi or unplug the cable. A stealer needs the connection to send data.

  3. 3

    Open Protection history

    In Windows Security > Virus & threat protection > Protection history, look for anything blocked or quarantined around the time you first started the game with the mod.

  4. 4

    Look at Task Manager

    Open Task Manager and look at the Processes tab for programs you do not know, or a javaw.exe that keeps running after you closed the game. javaw.exe is the normal Java runtime for Minecraft, so it alone proves nothing, but one that stays alive with the game closed is worth a look.

  5. 5

    Look at the Startup apps

    Open Settings > Apps > Startup and look for names you did not install. We do not know if these files add anything here, so a clean list does not clear the PC.

  6. 6

    Check your accounts from another device

    Look at the sign in activity of your email, Discord, Microsoft or Minecraft account, your bank and any exchange. Look for devices and places you do not know. This is quicker and more telling than any file check.

  7. 7

    A scan helps, but it does not clear the PC

    A scan with Microsoft Defender or another product can find known files. Java stealers are often new, so a clean scan is one data point, the same as a clean site test. We did not infect a PC, so the order of the plan is our judgement from Microsoft's page and the researchers' reports, not a tested result.

How to remove donutclients.st (Minecraft mod .jar files tagged stealer)

How to remove donutclients.st

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to donutclients.st or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever donutclients.st installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, Linux, an iPhone or an Android phone

Java mods are not tied to Windows, so the answer is different from a pure Windows trojan. Nothing we read says what these 30 files do on other systems.

Your deviceWhat we knowWhat to do
Mac or Linux with Minecraft JavaA .jar runs wherever Java runs. The fractureiser team said its virus targeted Windows and Linux. We do not know whether these files have code for other systemsIf you put one of these files in your mods folder, delete it, change your passwords from another device and run a scan. We do not give Mac or Linux steps we have not read from a vendor
iPhone or iPadMinecraft Java mods do not load on these devicesNothing to remove. If you typed a password on the site, change it
AndroidFabric .jar mods are a Minecraft Java feature, and the phone editions are a different version of the game. We found no source about these files on AndroidNothing to remove for this threat; change passwords if you entered any

After removal: passwords, accounts and prevention

If you ran one of the files: clean the PC, then protect what was taken

The PC is one half. The other half is everything saved or typed on it while the file ran. The order matters: another device first, then the PC.

Five steps in order: close the game and disconnect, change passwords from another device, delete the jar and run a Defender Offline scan, check what starts with Windows, reset Windows if unsure
The order of actions if a mod from this site ran on a PC. Steps follow Microsoft's page and the FTC; we did not test them on an infected PC.
  1. 1

    Close the game and stop using the PC for accounts

    Close Minecraft and the launcher. Disconnect from the network if you can. Do not log in anywhere from this PC until it is clean.

  2. 2

    Change passwords from a clean device

    Use a phone or another computer. Start with email, then Microsoft, Discord, Telegram, your launcher accounts, bank, work and crypto. The FTC says to pick a unique password, sign out of all devices and turn on two factor authentication if it is offered. Check the recovery email and phone number for anything that is not yours.

  3. 3

    Sign out other sessions and log out of tokens

    A stolen token can survive a password change on some services. Use each service's list of devices or sessions and sign out of all. For Discord and Telegram, remove devices you do not know.

  4. 4

    Move crypto first if a wallet was on the PC

    If a seed phrase or wallet file was ever on the PC, assume it is known. Create a new wallet and recovery phrase on a clean device and move the funds there.

  5. 5

    Delete the mod file

    Close Minecraft first, then delete the .jar you wrote down from the mods folder and the Downloads folder. Empty the Recycle Bin. Deleting the file stops it from running again, but it does not undo what already left the PC.

  6. 6

    Run Microsoft Defender Offline

    Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and restarts, and the scan takes about 15 minutes. If BitLocker is on, Microsoft says to suspend it first or the restart may ask for the recovery key. Results are under Protection history.

  7. 7

    Remove unknown programs

    Open Settings > Apps > Installed apps and uninstall programs you did not install and cannot explain. If you cannot tell, do not guess.

  8. 8

    If you are not sure, reset Windows

    The reset is under Settings > System > Recovery > Reset this PC. Choose Remove everything if the PC held anything valuable, because it does not depend on finding every piece. Back up documents first, and restore documents by hand, not programs. Reinstall Minecraft and mods from their official pages.

  9. 9

    Watch your money and accounts

    Check card statements and exchange logs for a few weeks and turn on alerts. The FTC says to report stolen personal information at IdentityTheft.gov, which gives a recovery plan.

  10. 10

    Tell your friends and server staff

    If your Discord or other accounts were used to send links, tell your contacts not to open them. If you are staff on a server, tell the other staff, so they can check your permissions.

Keep a PC out of this kind of trap

A mod is code that runs at full strength on your PC. The safest habit is to treat a mod download like an installer for a program.

Do

  • Get each mod from the page of its own project, or from a large mod platform, and check that the page belongs to the real author.
  • Prefer fewer mods. Every extra .jar is code you trust.
  • Keep Windows and Microsoft Defender updated.
  • Use a separate Microsoft, Discord and email password for each service, with two step sign in.
  • Keep crypto wallets and seed phrases off the PC where you game.

Don't

  • Do not download a pack of 30 free mods from a page that only repeats the names of famous projects.
  • Do not run cheat clients or hacked clients. They are the usual disguise for stealers.
  • Do not rely on the game running fine as proof that a mod is clean. Hidden hooks work beside a working mod.
  • Do not change passwords on the PC you suspect.
  • Do not rely on a quiet scan to say that you are safe.

Questions about donutclients.st (Minecraft mod .jar files tagged stealer)

What is donutclients.st?

It is a website that offers 30 free Minecraft mods for Fabric, and the malware tracking project URLhaus, run by abuse.ch, lists all 30 of its .jar files as malware downloads tagged stealer.

The files were reported on 7 October 2026. It is not a program on your PC. We did not download the files, so what they contain is not confirmed by us, and we do not know who runs the site.

Is donutclients.st safe?

No. Do not download or run files from it. Our own check was one plain request that found a live home page, which proves nothing about the files: a site can show a harmless page to one visitor and a different file to another.

The rating comes from the 30 URLhaus reports and their tags. All 30 were marked offline in our copy of the data, but offline addresses can come back or change.

Is it a virus if I only opened the website?

Opening the home page is much lower risk than running a file, and nothing we found says the page itself installs anything. The danger is in the .jar files.

If you saved one and put it into the mods folder, then started Minecraft, treat that as the infection case. If you downloaded a file but never ran it, delete it and empty the Recycle Bin. Our check cannot tell what a real browser would be shown.

What does stealer mean on a .jar file?

It is the reporter's label for a program that steals data, such as saved passwords, session tokens or crypto wallets. A .jar is a Java archive, the form of every Minecraft mod, and it runs with your Windows rights when the game loads it.

The tag is not proof, and we do not know which stealer family these files belong to or what exactly they take. Researchers describe Minecraft stealers that take launcher, Discord and Telegram tokens.

I put one of these mods into Minecraft. What should I do now?

Close the game and disconnect the PC. From another device change your passwords, starting with email, then Microsoft, Discord, your launcher accounts, bank and crypto, and sign out of all sessions.

Then delete the .jar, run a Microsoft Defender Offline scan and check Protection history and Startup apps. If you cannot be sure the PC is clean, reset Windows with Remove everything and restore only your documents.

Are the real Sodium, Iris or Baritone mods dangerous?

We are not saying that. The file names on this site copy the names of well known projects, but the real projects are published on their own pages, and URLhaus lists the files served from donutclients.st, not the originals.

Researchers describe attackers who alter a real mod and add a hidden hook. So the safe rule is to get each mod from its own project page and not from a pack site.

Can a mod steal my Minecraft or Discord account?

Yes, if the file is a stealer. Check Point Research describes Minecraft malware whose Java stage goes after launcher tokens and Discord and Telegram tokens. A token can let a stranger use an account without a password.

For these 30 files we cannot say what is taken. If you ran one, sign out of all sessions on each service and change the passwords from another device.

Does this affect Mac, Linux, iPhone or Android?

A Java .jar runs wherever Java runs, so a Mac or Linux PC with Minecraft Java can load a mod from this site.

We found nothing that says what these files do there, and the fractureiser team said its virus targeted Windows and Linux. On an iPhone, iPad or Android phone Minecraft Java mods do not load, so there is nothing to remove for this threat.

Will resetting Windows remove it, and are my accounts safe afterwards?

A reset with Remove everything wipes programs and startup entries, which is the answer that does not depend on finding every piece. It does not undo what was already taken.

Passwords, session tokens and crypto seed phrases that the stealer saw stay exposed until you change them, from another device, and turn on two step sign in. Restore documents by hand, not a full system image, and reinstall mods from their own pages.

Will Fortect remove donutclients.st?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For donutclients.st, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove likedrink.beer: a domain that served 27 Mirai botnet files for routers and other Linux devices, and what to do about it

likedrink.beer is a web address that URLhaus lists 27 times on 4 October 2026 for files named mirai followed by a chip type, such as mirai.arm7 and mirai.mips32. These are builds of the Mirai botnet program for...TRHigh riskUgnius Kiguolis ·

Remove niggersmp.net: a Minecraft cheat client site whose .jar downloads URLhaus tags SilentNet, and what to do if you ran one

niggersmp.net is a website that offers free Minecraft cheat clients, and URLhaus lists four of its .jar downloads (Radium_Client.jar, krypton.jar, 4E_Client.jar and Zyphers_Rig_Mod.jar) as malware tagged SilentNet. A...TRHigh riskUgnius Kiguolis ·

Remove Trojan:Win32/Ymacco

Ymacco Trojan is a piece of malware that can open backdoors and expose users to malicious websites Trojan:Win32/Ymacco is a is a highly dangerous cyber infection that aims at injectingTrojansHigh riskJulie Splinters ·

Remove ikovrsps.com: a server handing out Java game files and an EXE tagged stealer and CoinMiner, and what to do if you ran them

ikovrsps.com is a web address that URLhaus lists three times in two days for game style files (Ikov.jar, Mina.jar and gamefiles/image.exe), all tagged stealer and runelite, two also tagged CoinMiner. If you only saw...TRHigh riskUgnius Kiguolis ·

Questions and experiences: donutclients.st (Minecraft mod .jar files tagged stealer)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,462 members already hereReading, writing, commenting and voting. 0 verified · 187 joined this year