meteorrejects.net: a Minecraft cheat-addon site that URLhaus lists for SilentNet stealer files
meteorrejects.net is a polished website for a Minecraft addon called Meteor Rejects, and URLhaus lists three of its .jar files as malware tagged SilentNet and stealer. If you installed one of these files, treat the PC as compromised: change your passwords and Microsoft account from another device, then scan it offline.
Facts checked October 9, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If a meteor-rejects-addon .jar file downloaded from meteorrejects.net keeps coming back after uninstalling, a scan can find what reinstalls it.
Do it yourself · free Remove meteorrejects.net (SilentNet, Minecraft .jar) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Meteorrejects.net (SilentNet, Minecraft .jar): summary
| Type | A site offering Minecraft addon files; URLhaus lists its .jar files as malware tagged SilentNet and stealer |
|---|---|
| Risk | High if you installed one of its files: game, Microsoft, Discord and browser logins and crypto may have been taken |
| Symptoms | Often none. A meteor-rejects-addon .jar in the mods folder, sign-in alerts and messages you did not send are the signs |
| How to get rid of it | Close the game, change passwords from another device, move crypto, run a Microsoft Defender Offline scan, then back up documents and reinstall Windows if in doubt |
| Our check (9 October 2026) | One visit: a normal page, no pop-ups or notification request. A quiet site clears nothing; the danger rating comes from URLhaus |
| Running since / first seen | Domain registered 24 May 2026; first file reported 14 September 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Minecraft Java Edition addons; the sources we read describe Windows PCs |
|---|---|
| Detection names | No Microsoft detection name is known for these files, because we did not open them. The tag SilentNet is the reporter's label, and a Triage report on a different SilentNet file also lists WeedHack; neither was checked against these files |
| Name | Meteorrejects.net |
| Domain registered | 24 May 2026 |
| Evidence | 3 write-ups by security sites; details still limited |
| First seen | 14 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 9 October 2026 |
Facts checked on 9 October 2026 against our copy of the URLhaus data for meteorrejects.net, RDAP, one browser visit of our own, Check Point Research, a Triage sandbox report and Microsoft Learn. We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What meteorrejects.net is, and what we know about it
meteorrejects.net is a website that looks like the home of a free Minecraft addon, and the abuse.ch project URLhaus lists three .jar files on it as malware. The files carry the tag SilentNet; two also carry stealer, minecraft and jar. We did not download them, so this page rests on what URLhaus shows, what we saw on the site, and what other researchers wrote about files with the same tags.
- 1
What URLhaus lists
Three files under the site's main folder, all reported by the same person (GhostTypes): meteor-rejects-addon-1.21.11.jar on 14 September 2026, and meteor-rejects-addon-1.21.0.jar and meteor-rejects-addon-1.21.4.jar on 30 September 2026. All three were listed as online. The threat type is malware_download.
- 2
What the tags mean
SilentNet is a name given to a family of malicious Minecraft mods; the tag is the reporter's label. stealer says the file steals data. jar and minecraft say it is a Java archive for the game. The oldest file has only the SilentNet tag.
- 3
What we could not confirm
We did not download the files, so we do not know what exactly each does, which versions are affected or whether every file on the site is bad. We also did not check whether the real open-source project that the site imitates or claims to be hosts clean copies elsewhere.
- 4
What this means for you
If you only visited the page, you were not infected by that alone. The danger is for people who downloaded one of the .jar files and put it into the Minecraft mods folder, or ran it.
- Kind of threat
- A website that offers Minecraft addon files; URLhaus lists three of them as malware tagged SilentNet and stealer
- Looks like
- An open-source project page: 58 modules, 14 commands, an MIT licence, a download section, an FAQ and a GitHub link (our reading of the page text)
- Domain registered
- 24 May 2026, expires 24 May 2027, registrar Cloudflare, Inc.; record changed 9 September 2026 (RDAP, read 9 October 2026)
- URLhaus entries
- 3 file addresses, added 14 and 30 September 2026; all online when we read them
- Platform
- Minecraft Java Edition addons. Java runs on several systems; the sources we read describe Windows PCs
What meteorrejects.net (SilentNet, Minecraft .jar) does on an infected PC
What we checked on 9 October 2026, and what we could not
We opened https://meteorrejects.net/ once, from Lithuania, in an automated Chromium browser set to English. The page loaded normally. That is exactly what a malware site that wants to look trustworthy would do, so it clears nothing.
Our site test, 9 October 2026
- The page loadedStatus 200, titled Meteor Rejects, 58+ Modules and 14 Commands for Meteor Client. A dark red page with a feature list, a module library, a download section and an FAQ.
- Notification request, pop-ups, redirects, ad networks, service workerNone seen on this one visit. The page loaded only Cloudflare's script library, Google Fonts and Cloudflare Insights. There was no other address contacted.
- The claims on the pageThe page calls itself the definitive free addon, open source and MIT licensed. We did not check these claims, and a malicious site can copy a real project's description.
- URLhaus listingThree .jar files on this domain, tagged SilentNet; two also tagged stealer, minecraft and jar. All were online when we read the data.
- Why a normal-looking page is not a clean resultSites that hand out malware often show different things by country, device or visit. One visit that looks fine does not say the files are safe, and our test did not download them.
Dangerous: treat the files as malware The page itself did nothing alarming on one visit. The danger rating comes from the three URLhaus reports, not from our visit. Do not download or run files from this site.
What happened to meteorrejects.net, from registration to our test
The domain is about four and a half months old. The dates come from RDAP and from the URLhaus database.
24 May 2026
The domain is registered
RDAP shows meteorrejects.net registered on 24 May 2026 through the registrar Cloudflare, Inc., valid until 24 May 2027.
9 September 2026
The registration record changes
RDAP shows the record last changed on 9 September 2026. It does not say what changed.
14 September 2026
The first file is reported
At about 06:01 UTC the reporter GhostTypes adds meteor-rejects-addon-1.21.11.jar to URLhaus with the tag SilentNet. This is the first time URLhaus sees the host.
30 September 2026
Two more files are reported
At about 09:58 UTC the same reporter adds the 1.21.0 and 1.21.4 versions, tagged jar, minecraft, SilentNet and stealer.
9 October 2026
Our test loads the site, and the files are still listed
The site answers with a normal page. All three files are still marked online in the data we read the same day.

meteorrejects.net in our test browser on 9 October 2026. Nothing on the page warns of the files that URLhaus lists.
We could not read the URLhaus pages themselves, because they ask for a browser check. The entries above come from the same data in our own database, which holds the URLhaus feed.
How a fake game addon gets you to install it
Nothing here uses a security hole. You download a file because it promises something, and you install it yourself. Check Point described the same pattern for fake Minecraft cheat mods; we did not see this site's download step.
- 1
You search for a cheat or an addon
Players of Minecraft utility clients look for extra modules. A site named after the addon, with a Get Free button and version buttons for 1.21.0, 1.21.4 and 1.21.11, fits that search.
- 2
You download a .jar file
A .jar is a Java archive. Fabric-style mods are put into the mods folder of Minecraft by hand, which is why a victim installs the file without any warning from Windows.
- 3
The game starts the file
Minecraft loads the mod when the game starts. Check Point describes a Java loader that checks for virtual machines and analysis tools, then fetches the next stage; a second Java stage runs inside Minecraft and collects account data.
- 4
A third stage may follow
In the Check Point case a .NET stealer was downloaded by the second stage and sent its results out through a Discord webhook. We do not know whether the meteorrejects.net files do this.
- 5
Antivirus may stay quiet
Check Point says Java loaders of this kind went largely undetected by antivirus engines and sandboxes, which often lack the Minecraft parts needed to trigger the payload. A quiet scan therefore proves little.
Check Point's report is about a different campaign, the Stargazers Ghost Network, which hosted fake mods on GitHub. We use it only for how the chain works; we do not say the two are linked.
What the SilentNet tag tells us, and what it does not
The tag comes from outside reporters, and the public record on it is thin. This is what the pages we read say.
| Question | What we found | Source |
|---|---|---|
| What is SilentNet? | A signature name used for malicious Minecraft Fabric mods. One Triage report on a file called Krypton_Client.jar scores it 10 out of 10, tags it RAT, stealer and trojan, and links it to the SilentNet and WeedHack families | Triage report, read 9 October 2026 |
| What does that sample do? | The report's own text says it steals session tokens, downloads and runs more payloads, and persists through hidden means. It gives no domains, addresses or file names for these | Triage report |
| Is it the same as meteorrejects.net's files? | Not known. The tag is the same; the sample is a different file. We did not compare the files | Our reading |
| How did antivirus do? | In that report the static analysis matched SilentNet and WeedHack signatures, while two sandbox runs on Windows 10 and 11 raised none | Triage report |
| What is not known? | Which servers the files talk to, what exactly they take, and whether they run on Mac or Linux. No source we read says | Our reading |
What meteorrejects.net (SilentNet, Minecraft .jar) can steal or download
What a fake Minecraft addon can take
We do not know the exact list for these three files. Check Point lists what the stealer in a comparable Minecraft mod campaign collected, and Triage lists session tokens for a SilentNet sample. Plan for the wider list.
Reported as taken in comparable Minecraft mod malware
- Minecraft session tokens and account files
- Feather, Essential and Lunar launcher data
- Discord data
- Telegram data
- Browser passwords (Chromium, Edge, Firefox)
- Cryptocurrency wallets
- VPN configs
- Steam data
- FileZilla data
- Clipboard contents
- A list of running processes
- Screenshots
| Data | What can happen | Source |
|---|---|---|
| Minecraft session token | Someone else can use your game account and, through it, your linked Microsoft account sign-in | Check Point; Triage |
| Discord and Telegram data | Your chats and logins can be used to message your friends with the same lure | Check Point |
| Browser logins | Saved passwords and cookies for email, banks and shops | Check Point |
| Crypto wallets | Funds that cannot be recovered once moved | Check Point |
| More payloads | A downloader can add more malware later, so the first file may not be the last | Triage |
What this can cost you
Visiting the page costs nothing. The risks below apply to a PC where one of the .jar files was put into the mods folder or run.
- High
Account takeover
A stolen session token lets someone use your game, Discord or browser accounts without your password. A new password alone may not end a stolen session.
- High
Crypto theft
Wallet files are a main target for stealers. Move funds first, from another device.
- Medium
More malware installed
Triage says a sample with the same tags downloads and runs additional payloads. A hidden program may start again after you remove the mod.
- Medium
Friends and servers
If your Discord is taken over, the lure can be sent to your friends. If you run a server, tell its members.
- Medium
Children's accounts
Many Minecraft players are young. A parent should check the family's Microsoft account for sign-ins they do not know.
- Low
Nothing, if you only saw the page
A page visit, a warning or a blocked link is not an infection.
What you may notice, and what you may not
Most victims notice nothing at first. The signs below follow from what the reports say these files do.
| Sign | What it means |
|---|---|
| A .jar named meteor-rejects-addon in the mods folder | The file you installed. Its name matches the URLhaus entries. Press the Windows key + R, type %appdata%\.minecraft\mods and press Enter to look |
| Game or launcher logged out by itself | A session that was stolen and used elsewhere can end yours |
| Discord messages you did not send | A taken-over account sending the same download link |
| Sign-in alerts for your Microsoft account from other places | Someone else using a stolen token or password |
| Slow PC or an unknown java or javaw process | A hidden second stage. This is our reading, and not every infection shows it |
| Nothing at all | Stealers are built to finish quickly and stay quiet |
How to check the PC for meteorrejects.net (SilentNet, Minecraft .jar)
How people end up on a page like this
We do not know how visitors reach meteorrejects.net, and no source says. These are common routes for fake game mods.
- 1
A search for the addon's name
A page named after a popular addon can show up beside the real project when a player searches for a download.
- 2
A video or a chat link
A video description or a Discord message that says free cheats or the best addon points to a download page.
- 3
A GitHub link that copies a real project
Check Point describes fake mod repositories on GitHub that were starred by many accounts to look trusted.
- 4
A friend whose account was taken
A message from someone you know carries more weight, and it is how a stolen Discord account spreads the lure.
Check your PC before you delete anything
Start with the question that matters: did you download a meteor-rejects-addon .jar from meteorrejects.net and put it in Minecraft's mods folder, or run it? If yes, follow the numbered plan on this page, because a clean-looking check does not clear a PC. If you are not sure, do these checks first. None of them deletes anything.
While you check, do not start Minecraft, and do not use the PC for banking, email or crypto. If you can, disconnect it from Wi-Fi and the network cable.

- 1
Look in the mods folder
Press Windows key + R, type
%appdata%\.minecraft\modsand press Enter. Look for a file named meteor-rejects-addon with a version number, or any mod you do not remember adding. Do not open it; write down the name and date. Launchers such as Feather, Essential or Lunar keep their own folders, so check them too. - 2
Check Downloads
Open File Explorer > Downloads and look for .jar files from the day you got the addon. Right-click a file and choose Properties to see its date. Do not double-click a .jar.
- 3
Look for a scheduled task you did not make
Press the Windows key, type Task Scheduler and open it. Select Task Scheduler Library and read the names and the Actions tab of any task that is new or has a random name. Do not delete anything yet.
- 4
Look in the Startup folder
Press Windows key + R, type
shell:startupand press Enter. A file you did not put there is a sign of something that starts again. Note it. - 5
Check Windows Security
Open Windows Security > Virus & threat protection > Protection history. On Windows 10 the same page is under Settings > Update & Security > Windows Security. Look for detections around the time of the download. A clean list lowers doubt; it does not remove it.
How to remove meteorrejects.net (SilentNet, Minecraft .jar)
How to remove meteorrejects.net
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to meteorrejects.net or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever meteorrejects.net installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Scan from outside Windows: Microsoft Defender Offline
An offline scan runs before the normal Windows starts, so a hidden program cannot hide from it as easily. Microsoft's page says it targets malware that tries to bypass the Windows shell, such as rootkits.
- 1
Prepare
Save your work and close programs. Microsoft says the scan takes about 15 minutes and restarts the PC. It needs an administrator account and Windows Recovery Environment turned on. To check, open a Command Prompt as administrator and run
reagentc /info; if it says Disabled, runreagentc /enable. - 2
Suspend BitLocker if it is on
If BitLocker protects the system drive, suspend it first. Otherwise the PC may ask for your recovery key when it restarts into the offline scan.
- 3
Start the scan
Open Windows Security > Virus & threat protection > Scan options. Choose Microsoft Defender Offline scan and select Scan now. Agree to the prompts. The PC signs you out, restarts into the scan and starts Windows again when it ends.
- 4
Read the result
Open Windows Security > Virus & threat protection > Protection history. Microsoft says the scan works on x64 Windows 10 and 11, not on ARM, and needs Microsoft Defender Antivirus as the main antivirus.
- 5
Remove the mod and the launcher cache
Only after the scan, delete the meteor-rejects-addon file from the mods folder. Download Minecraft mods only from the maker's own page or from a source you checked, and never reuse this file.
- 6
Do not stop there
A scan that finds nothing does not prove the PC is clean, because Java loaders of this kind can go unnoticed. If the file ran, the safest end of the plan is to back up documents and reinstall Windows.
If you play on a Mac, a phone or a console
The sources we read describe Windows PCs. A .jar can run anywhere Java does, so the file is not limited to Windows by itself.
| Your device | What we know | What to do |
|---|---|---|
| Mac or Linux with Minecraft Java | A .jar does not care about the system. Whether these files act on other systems is not stated by any source we read | Treat it as the same case: change passwords from another device, remove the file and check our Mac guides for the cleaning steps; do not follow the Windows steps |
| Bedrock Edition, phone, tablet or console | Fabric-style .jar mods do not run there | Nothing to remove. If you typed passwords on the page, change them |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
The PC is one half. The other half is everything that was on it, which the attackers may already have. The order matters: other device first, then crypto, then the PC.
- 1
Change your Microsoft account password from a clean device
Use a phone or another computer and the Microsoft account page. Then sign out everywhere. A stolen game token can ride on a Microsoft account sign-in.
- 2
Change Discord and other passwords, and revoke sessions
Change Discord, email, bank and shop passwords. In each account use the option to log out of all devices, because a token can outlive a password change.
- 3
Warn your friends and your server
If your Discord sent the link, tell people not to open it. Server owners should say which file name to avoid.
- 4
Move crypto first if a wallet was on the PC
If a recovery phrase may have been exposed, move the funds to a new wallet with a new phrase made on a clean device.
- 5
Turn on two-factor sign-in
Use an authenticator app or a security key where the account allows it.
- 6
Back up documents and reinstall Windows if in doubt
Copy only documents and photos to an external drive. In Settings > System > Recovery on Windows 11, or Settings > Update & Security > Recovery on Windows 10, choose to reset the PC and remove everything.
Keep a gamer PC out of this kind of trap
The rule that would have stopped this: a mod is code you run with your own rights, so it is only as safe as the place you got it from.
Do
- Get mods only from the maker's official page, and compare the link with the one in the project's own repository.
- Treat a polished page with a Get Free button and no named authors with suspicion.
- Keep Windows and Windows Security up to date and turned on.
- Use an authenticator app for your Microsoft and Discord accounts.
- Run Minecraft under a normal account, not on a PC that holds work or banking logins.
Don't
- Do not download cheat addons from sites that came from a video or a chat link.
- Do not double-click a .jar file from the Downloads folder.
- Do not rely on a quiet antivirus scan to say a .jar is safe.
- Do not reuse one password for the game, Discord and email.
- Do not keep a wallet recovery phrase in a file on a gaming PC.
Questions about meteorrejects.net (SilentNet, Minecraft .jar)
What is meteorrejects.net?
It is a website that presents a free Minecraft addon called Meteor Rejects, with a module list, a download section and a FAQ. URLhaus lists three .jar files on it as malware, tagged SilentNet, two of them also tagged stealer.
The domain was registered on 24 May 2026. In our test on 9 October 2026 the page loaded normally, with no pop-ups and no notification request.
A normal page does not make the files safe. If you only visited, you are not infected by that. If you downloaded or installed a file, use the cleaning steps on this page.
Is Meteor Rejects a virus?
The real name belongs to an addon idea, so we separate the name from this site. The files on meteorrejects.net are listed by URLhaus as malware, so do not use them. We did not download them and did not check whether the open-source project that the site describes has clean files elsewhere.
If you want the addon, find the project's own repository and check its links yourself, or skip it. A page that copies a project's description and offers a Get Free button is not proof that it is the project.
What is SilentNet?
SilentNet is a tag used for malicious Minecraft Fabric mods. A Triage sandbox report on a file called Krypton_Client.jar scores it 10 out of 10 and links the tag to the WeedHack family, with a RAT, stealer and trojan label.
The report says such a mod steals session tokens, downloads and runs more payloads, and persists through hidden means. It gives no more detail. We did not compare it with the meteorrejects.net files, so we say only that they carry the same tag and plan for the same kind of risk.
I installed a meteor-rejects-addon file. What do I do now?
Close Minecraft and its launcher and disconnect the PC from the network. From another device change your Microsoft account password, then Discord, email and bank passwords, and sign out of all devices. Move any crypto to a new wallet.
Then run a Microsoft Defender Offline scan on the PC and delete the file from the mods folder. Because Java loaders can go unnoticed, the safest end is to back up documents and reinstall Windows. Warn friends if your Discord could have sent the link.
What if I only visited the site and downloaded nothing?
Visiting a page does not usually infect a PC by itself. The danger starts when you download a .jar and put it into the mods folder or run it. If you downloaded nothing, close the tab, do not go back, and run a normal scan in Windows Security as a precaution.
If you downloaded a file but never opened it, delete it from Downloads and empty the Recycle Bin, and do not double-click it. If you did open it, treat it as installed.
Where is the Minecraft mods folder on Windows?
For the standard launcher, press the Windows key and R together, type %appdata%\.minecraft\mods and press Enter. The folder holds the .jar files the game loads. Look for meteor-rejects-addon with a version number, or any file you do not remember adding.
Launchers such as Feather, Essential and Lunar may keep their own folders, so check them as well. Do not open a suspicious file. Note its name and date, then remove it only after the offline scan.
Will a scan with Windows Security remove it?
Microsoft Defender can detect many malicious files, and you should run it. But we cannot promise it finds the files from this site, because we do not know what they install, and Check Point says Java loaders of this kind went largely undetected by antivirus engines.
The stronger step is the Microsoft Defender Offline scan, which runs before Windows starts. If the mod ran, reinstalling Windows is the surest cleaning. We know of no removal tool that we have tested against these files.
Was my Minecraft or Microsoft account stolen?
We cannot tell from the outside. The report on a SilentNet sample says it steals session tokens, and Check Point's account of a comparable campaign lists Minecraft account files and launcher data. Look at your Microsoft account's recent sign-in activity from another device, and sign out everywhere.
Change the password and turn on two-factor sign-in. If you see sign-ins from places you were not, assume the account was taken and tell Microsoft support, and check linked Discord and email accounts as well.
Why did our test of meteorrejects.net look normal?
Our automated browser loaded the page with a status 200, a feature list and a module library, and it saw no pop-ups, redirects or notification request. A malware site that wants downloads needs to look trustworthy, so a normal page is expected.
The harm is in the files, not the page, and we did not download them. Sites also can show different things by country, device or visit. One visit that looks fine clears nothing, and the URLhaus listing is why we rate the files as dangerous.
Will Fortect remove meteorrejects.net?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For meteorrejects.net, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- URLhaus (abuse.ch): host page for meteorrejects.net (entries read from our copy of the feed) (read October 9, 2026)
- RDAP registration record for meteorrejects.net (read October 9, 2026)
- Check Point Research: Minecraft mod malware (Stargazers Ghost Network) (read October 9, 2026)
- Triage sandbox report: Krypton_Client.jar (SilentNet, WeedHack) (read October 9, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (read October 9, 2026)