niggersmp.net: a Minecraft cheat client site whose .jar downloads URLhaus tags SilentNet, and what to do if you ran one

niggersmp.net is a website that offers free Minecraft cheat clients, and URLhaus lists four of its .jar downloads (Radium_Client.jar, krypton.jar, 4E_Client.jar and Zyphers_Rig_Mod.jar) as malware tagged SilentNet. A .jar file does nothing by being on a server; it matters only if someone ran it.

If you only saw the name, nothing is proven; if you ran one of these files, treat the PC and every account you used on it as exposed:

  • change passwords from another device
  • then scan and clean
  • reset the system

Facts checked October 11, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Programs like a .jar file downloaded from niggersmp.net and run through Java or the Minecraft launcher usually arrive in groups; a free scan lists the companions that are easy to miss.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove niggersmp.net (SilentNet, Minecraft client .jar files) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of four URLhaus entries for niggersmp.net, folder downloads, files Radium_Client.jar, krypton.jar, 4E_Client.jar and Zyphers_Rig_Mod.jar, all online, tagged SilentNet
The four URLhaus entries for niggersmp.net as we hold them on 11 October 2026. We made no browser visit and downloaded nothing; this table of reports, not a screenshot of the site, is the main evidence.

Niggersmp.net (SilentNet, Minecraft client .jar files): summary

TypeA website offering Minecraft cheat clients; URLhaus lists four of its .jar files as malware tagged SilentNet
RiskHigh if you ran one of the files: your Minecraft session and other logins may be taken. Low if you only saw the name
SymptomsOften none. A Java process running when Minecraft is closed, or account activity you did not start, are the signs the reports suggest
How to get rid of itChange passwords from another device, run Microsoft Defender Offline, remove the file and its startup entries, and reset the system if you are not sure
Our check (11 October 2026)One plain request to the home page: status 200 behind Cloudflare, title about free Minecraft cheat clients. A quiet page clears nothing; the rating comes from URLhaus
Running since / first seenDomain registered 5 April 2026; the four files first reported 10 October 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformComputers that run Java and Minecraft: Java Edition. Nothing we read says phones or consoles are affected
Detection namesNo Microsoft detection name is known for these files, because we did not open them. The abuse.ch tag is SilentNet
NameNiggersmp.net
Domain registered5 April 2026
Evidence4 write-ups by security sites; details still limited
First seen10 October 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked11 October 2026

Facts checked on 11 October 2026 against the URLhaus data for niggersmp.net held in our database (the abuse.ch host page itself is not fetched by our tool), RDAP, one plain request from our server, and pages by MalwareBazaar, Check Point Research, Microsoft and the FTC. We did not download the files and we infected no computer; the removal steps follow Microsoft's pages and were not tried on a live infection.

What niggersmp.net is, and what we know about it

niggersmp.net is not a program on your computer. It is a web address that the abuse.ch project URLhaus lists as a place where malware was served: four Java archive files in a folder called downloads. The domain name contains a racial slur; we print it only because the reports name it. We found no public write-up of this address, so this page rests on URLhaus, our own plain request and vendor research on Minecraft malware.

  1. 1

    What URLhaus lists

    Four file addresses on niggersmp.net, all in the folder /downloads/ and all ending in .jar: Radium_Client.jar, krypton.jar, 4E_Client.jar and Zyphers_Rig_Mod.jar. All four were added at the same moment, 16:40 UTC on 10 October 2026, by one reporter with the handle wok. All four are marked online, all carry the threat label malware_download, and all carry one tag: SilentNet.

  2. 2

    What the names suggest

    The file names look like Minecraft cheat clients and mods, and the home page of the site calls itself a place for free Minecraft cheat clients and mods. That fits the lure that researchers describe for Minecraft malware: a cheat or a mod that players want, offered for free. It is our reading of the names, not something the reports say.

  3. 3

    What the tag means

    SilentNet is a name used on the abuse.ch malware sample site MalwareBazaar for Java malware aimed at Minecraft. One MalwareBazaar entry we read is a fake build of a known Minecraft client on a lookalike site, labelled SilentNet, and it describes stealing the Minecraft session and starting again as a hidden process. That entry is a different file from the four here. We did not download these four, so we cannot say what is inside them.

  4. 4

    What this means for you

    If you only saw the name in a log, a blocked request or a warning, you are not infected by that alone. The risk is for a person who downloaded one of these .jar files and ran it, usually by double clicking it or by dropping it into the Minecraft mods folder.

Kind of threat
A website offering Minecraft cheat clients; four of its .jar downloads are reported as malware tagged SilentNet
Where the files are
hxxps://niggersmp[.]net/downloads/ with the names Radium_Client.jar, krypton.jar, 4E_Client.jar and Zyphers_Rig_Mod.jar
Domain registered
5 April 2026 through NameCheap, Inc.; status client transfer prohibited (RDAP, read 10 October 2026). The domain is about six months old
URLhaus entries
4 file addresses, all added 10 October 2026 at 16:40 UTC by the reporter wok; all 4 online in our copy of the data
File type
.jar, a Java archive. It runs wherever Java is installed, and Minecraft: Java Edition installs its own Java
Platform
Any computer that runs Java and Minecraft: Java Edition (Windows, Mac, Linux). Nothing we read says iPhone, Android or the console editions are affected

What niggersmp.net (SilentNet, Minecraft client .jar files) does on an infected PC

What we checked on 11 October 2026, and what we could not

Our check was one plain request to the home page from our server, without a browser and without clicks. It does not show what a visitor with a real browser, another country or a second visit would be shown. A quiet answer clears nothing.

Our request, 11 October 2026

  • The home page answeredThe server answered with status 200 and no redirect. The page title is Cheat Clients, Free Minecraft Cheat Clients and Mods. The site sits behind Cloudflare, a service that hides the real server and can show different answers to different visitors.
  • Notification requestThe page text of this one plain request did not mention the browser notification system. We ran no browser, so a request that appears after a click or a delay would not show.
  • Why that is not a clean resultA site that hands out malware can look like an ordinary download page. The files, not the front page, are what URLhaus reports, and we did not open them.
  • URLhaus listingFour .jar files in /downloads/ tagged SilentNet and malware_download; all four online in our copy of the data on 11 October 2026.
  • Downloads and the files themselvesWe did not download any .jar and we ran nothing. We cannot tell you what the files contain, where they send data or whether they differ for different visitors.

Dangerous: do not download or run files from this site Our request was one visit and proves nothing either way. The rating comes from the four URLhaus reports and their tag, not from the front page. Do not download from this address.

What happened to niggersmp.net, from registration to our check

The domain is young and the reports are a day old. The dates come from RDAP and from the URLhaus data we hold; the times are UTC.

  1. 5 April 2026

    The domain is registered

    RDAP shows niggersmp.net registered on 5 April 2026 through NameCheap, Inc., with the status client transfer prohibited. That status is a common lock against moving a domain away and says nothing about the content.

  2. 10 October 2026, 16:40 UTC

    Four .jar files are reported

    The reporter wok adds Radium_Client.jar, krypton.jar, 4E_Client.jar and Zyphers_Rig_Mod.jar in one batch. Each is labelled malware_download and tagged SilentNet. All are online at the time of listing.

  3. 11 October 2026

    Our request

    A plain request to the home page returns status 200 through Cloudflare, with the title Cheat Clients, Free Minecraft Cheat Clients and Mods. All four reported files are still marked online in our data.

    Table of the four URLhaus entries for niggersmp.net with file names, online status and the SilentNet tag
    The four URLhaus entries for niggersmp.net on 11 October 2026: one folder, four client names, one tag.

What the pattern suggests, and what it does not: four different client names added in one batch on a domain six months old looks like a site built to offer many cheat downloads, with several of them carrying the same malware family. That is our reading of the dates and names. No report says who runs the site or whether the owner knows what the files contain.

How a .jar cheat client can steal from a player

A .jar file is a program. Unlike a picture or a document, it is made to run, and a Minecraft client or mod runs with the same rights as you. We did not open the files on niggersmp.net; this is how Check Point Research describes a Minecraft cheat malware campaign it studied in 2025, and how the MalwareBazaar entry describes a SilentNet sample.

Five steps of a fake Minecraft cheat client: a player finds a free client, downloads the jar, runs it, a stealer collects the Minecraft session and logins, and the data is sent to the attacker
The chain as vendors describe it for Minecraft cheat malware. Which of these steps the four files here perform is not confirmed.
  1. 1

    The lure is a free cheat

    Check Point Research (18 June 2025) describes fake cheat and macro tools for Minecraft, called Oringo and Taunahi, shared through the Stargazers Ghost Network, a service that runs many fake accounts on GitHub to make malware look popular. Players look for free clients, find a page that offers one and download it.

  2. 2

    The first stage is Java

    In that campaign the first stage downloader and the second stage stealer were written in Java and needed Minecraft to be installed. That matches a .jar file that a player runs on purpose. Check Point reports a third stage written in .NET with wider stealing functions.

  3. 3

    The client may still work

    A common trick is to hide the malicious part inside something that behaves like the promised client, so the player sees a menu and thinks all is well. We do not know whether the files on this site do this.

  4. 4

    The Minecraft session and more are taken

    The MalwareBazaar entry we read, a fake build of a known client labelled SilentNet, describes stealing the Minecraft session and starting again as a hidden process. Check Point's campaign also went for other stored logins. A stolen session lets someone act as the player's account.

  5. 5

    The data goes to the attacker

    The stolen data is sent to a server the attacker controls. We do not know where the four files here would send it, because we did not run them.

A caution on names: SilentNet is a label used by researchers and by the sample site, not a product name from a large vendor, and we did not find a full vendor analysis of it. Where we say what SilentNet does, we mean what one listed sample is described as doing, not a proven description of these four files.

What we can and cannot say about the SilentNet tag

The tag is the only technical fact URLhaus gives for these four files. It is worth being exact about what it supports.

Sources: MalwareBazaar sample page read 11 October 2026, and our own search for a vendor analysis.
QuestionWhat the sources saySource
Is the tag specific to Minecraft?The sample we read is a Minecraft client for a named Minecraft version, labelled SilentNetMalwareBazaar
What does the sample do?Steals the Minecraft session and relaunches itself as a hidden process, according to its entryMalwareBazaar
Do the four files here do the same?Not known. The tag is the same, the files were not opened by usNot available
Is there a vendor analysis of the tag?We did not find one from a large vendor. Treat the name as a researcher labelOur search
Are the files harmless clients with a false alarm?Not ruled out by anything we can show, but four files tagged by a reporter on an unvetted download site is not a result to bet an account onOur reading
What is the Microsoft detection name?Not known for these files. Do not trust a page that invents oneNot available

What niggersmp.net (SilentNet, Minecraft client .jar files) can steal or download

What Minecraft stealer malware can take

The list below is what the sources say Minecraft-targeting stealers go for. It is not a list of what these four files do; for that we have no evidence.

Reported as possible for this kind of malware

  • Your Minecraft session
  • Microsoft account sign in data
  • Saved browser passwords
  • Discord login data
  • Cryptocurrency wallet data
  • Files and screenshots
  • A hidden process that starts again
  • Extra malware downloaded
Sources: MalwareBazaar and Check Point Research, read 11 October 2026.
DataDetailSource
Minecraft sessionStolen so the attacker can act as your account; described for a SilentNet-labelled sampleMalwareBazaar
Other stored loginsCheck Point describes a stealer stage in the campaign it studied that goes beyond the gameCheck Point Research
PersistenceThe sample starts again as a hidden processMalwareBazaar

What this can cost you

Reading the site or seeing its name costs nothing. The risks below apply to a computer where one of these .jar files was run.

  • High

    Your Microsoft and Minecraft account

    A stolen session can let someone use the account without the password. Changing the password from the same computer does not help while the stealer is still running.

  • High

    Other logins on the same computer

    If the file goes beyond the game, as the campaign Check Point describes does, browser passwords and other stored logins are at risk, including Discord and email. Email matters most, because it resets everything else.

  • Medium

    Crypto wallets

    If a wallet or seed phrase was ever on the computer, assume it may be known. Crypto sent away cannot be called back.

  • Medium

    More malware

    A first stage can fetch more. If the PC is shared, other family members' accounts are in question too.

  • Medium

    Children and shared PCs

    Cheat clients attract young players. A child who ran a file on a family computer can expose the parents' logins as well.

  • Low

    Nothing, if you only saw the name

    A name in a log, a block list or a warning is not an infection.

What you may notice, and what you may not

Stealers try to be quiet. The signs below come from the sources and from what they imply. None is certain and many victims notice nothing.

SignWhat the reports show
A Java process you did not startThe SilentNet-labelled sample is described as relaunching as a hidden process. A java or javaw process running while Minecraft is closed is worth a look
Your Minecraft or Microsoft account used by someone elseFollows from a stolen session. Look for sign ins from new places and for changes to your skin, name or server access. This is our reading, not a quote
Password reset emails or login alerts you did not ask forFollows from stolen logins
Messages sent from your Discord accountDiscord token theft is described for some Minecraft malware; we cannot say it applies here
A client that does nothing, crashes or shows only a blank windowPossible when the file was only a carrier. Not proof either way
Nothing at allQuiet running is the point of a stealer

How to check the PC for niggersmp.net (SilentNet, Minecraft client .jar files)

How a person ends up with one of these files

Unlike a loader fetching a picture, this is a download a person chooses. That is why the realistic routes are about trust: a link in a video, a chat or a search result that promises something free for the game.

  1. 1

    A search for a free cheat client

    The site calls itself a place for free Minecraft cheat clients and mods, so a player who searches for a free client can land on it. Search results are one of the routes the Minecraft malware reports describe.

  2. 2

    A link shared in a video, server or chat

    Cheat links spread in video descriptions, game chats and Discord servers. We have no evidence of how links to this site are shared; this is a route that is known for the type.

  3. 3

    A file renamed to look like a real mod

    Some malware uses the name of a well known mod or library, so the file looks routine in the mods folder. Check where a mod came from, not just its name.

  4. 4

    The Minecraft launcher is not the source

    A file only reaches the game if you put it there. The official launcher does not fetch cheat clients from sites like this, so a client from a download page is something a person installed by hand.

Check your computer before you delete anything

Start with the question that matters: did you or someone on this computer download a .jar from niggersmp.net, or run a free cheat client from anywhere? If you saw the name in a firewall or DNS log, find the device that asked. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.

While you check, stop using the computer for banking, email, school, work or crypto. If you can, disconnect it from the network.

  1. 1

    Disconnect first

    Turn off Wi-Fi or unplug the cable. A stealer that is already running needs the connection to send data.

  2. 2

    Find the file

    Open the Downloads folder and the Minecraft mods folder and look for Radium_Client.jar, krypton.jar, 4E_Client.jar or Zyphers_Rig_Mod.jar, or any client you got from a site rather than from its makers. Note the names and the date; do not run anything. Do not delete yet if you want to give the file to a security vendor.

  3. 3

    Open Protection history

    In Windows Security > Virus & threat protection, choose Scan options and then Protection history. Look for any detection or block at the time you downloaded or ran the file. Microsoft says the results of an offline scan appear in the same place.

  4. 4

    Look at running programs

    Open Task Manager and look for java.exe or javaw.exe when Minecraft is closed, and for programs you do not know with a lot of network use. A Java process is normal while the game runs and is not proof of anything when it does.

  5. 5

    Look at Startup apps

    Open Settings > Apps > Startup and look for entries you did not make. A program that starts again after a restart is one way a hidden process stays.

  6. 6

    Check your accounts from another device

    Look at the sign in activity of your Microsoft account, email, Discord and any crypto exchange, and at wallet balances. This is quicker than any file check, and it must be done from a device that never ran the file.

  7. 7

    A scan helps, but it does not clear the computer

    A scan with Microsoft Defender or another product can find known files. A clean result is one data point, like a clean site test. We did not infect a computer, so the order of this plan is our judgement from Microsoft's pages, not a tested result.

How to remove niggersmp.net (SilentNet, Minecraft client .jar files)

How to remove niggersmp.net

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to niggersmp.net or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever niggersmp.net installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, Linux, a phone or a console

A .jar file is not tied to Windows. Whether these four files only work on Windows is not known. Our sources describe Java malware that needs Minecraft: Java Edition and a computer that runs Java.

Your deviceWhat we knowWhat to do
Mac or Linux with Minecraft: Java EditionJava runs there, so a .jar can start. We do not know whether these files contain code for those systemsIf you ran one, treat it as exposed: change passwords from another device and sign out of your Microsoft account everywhere. We did not verify Mac removal steps, so for a Mac the safe answer is a clean macOS reinstall after you save documents
iPhone or iPadJava .jar files do not run in the normal iOS apps, and no source mentions this threat on iOSNothing to remove. If you typed passwords on a page of the site, change them
AndroidNo source mentions this threat on AndroidNothing to remove for this threat; change passwords if you entered any
Console or Bedrock EditionCheat clients like these target the Java EditionNothing to remove for this threat

After removal: passwords, accounts and prevention

After a clean computer: protect what was taken

The computer is one half. The other half is everything you typed or stored on it while the file was there. The order matters: another device first, then the computer.

Five steps in order: disconnect the computer, change passwords from another device, sign out everywhere, run a Defender Offline scan, reset the system if unsure
The order of actions if a Minecraft cheat client was run. Steps follow Microsoft and FTC pages; we did not test them on an infected computer.
  1. 1

    Change passwords from a clean device

    Start with email, because it resets everything else, then your Microsoft account, Discord, bank, school or work and crypto. The FTC says to choose a unique, strong password, and gives 12 to 15 characters or a passphrase as a guide. Anything typed on the computer after the file ran may already be known.

  2. 2

    Sign out everywhere and turn on two step sign in

    The FTC says to sign out of the account on all devices and to turn on two factor authentication if it is offered, so a password alone does not let anyone in. Update the recovery email and phone number while you are there, and check for email forwarding rules you did not make.

  3. 3

    Move crypto first if a wallet was on the computer

    If a seed phrase or wallet file was ever on it, assume it is known. Create a new wallet and recovery phrase on a clean device and move the funds there.

  4. 4

    Run Microsoft Defender Offline

    Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and restarts, and the scan takes about 15 minutes. If BitLocker is on, Microsoft says to suspend it first or the restart may ask for the recovery key. Results are under Protection history.

  5. 5

    Remove the file and what it started

    Once you have noted the names, delete the .jar from Downloads and the mods folder, and remove startup entries you can tie to it. If you cannot tell, do not guess: the safe answer is the reset below.

  6. 6

    If you are not sure, reset Windows

    Microsoft's recovery page says Reset this PC reinstalls Windows and can be started from Settings or from the Windows Recovery Environment under Troubleshoot > Reset this PC. You can choose to keep your personal files or remove everything; in both cases apps and settings are removed. If the computer ran the file with accounts open, the full wipe is the answer that does not depend on finding every piece. Back up first; with BitLocker you need the recovery key.

  7. 7

    Restore only documents by hand

    Copy back documents and photos, not programs and not .jar files. Install Minecraft again from the official launcher, and get mods only from their makers or well known mod sites.

  8. 8

    Report and watch

    Check card statements and exchange logs for a few weeks and turn on alerts. The FTC says to report stolen personal information at IdentityTheft.gov for a recovery plan. Tell friends and server admins if your Discord account sent links.

If you run a site and the file is yours

A listing can mean a site built to spread malware, and it can also mean a hacked or careless site. We do not know which this is, and we do not claim to.

  1. 1

    Check whether you uploaded the files

    If the files in the downloads folder are not yours, or you did not put them there, your site may be hacked. Remove them, and change every password and key for the site, the hosting account and the domain account.

  2. 2

    Rebuild the clients from source you trust

    If you do make clients, build them from source you control and publish a file hash next to each download, so a player can check it. An unknown binary from a third party is the risk for you as well.

  3. 3

    Ask for a review

    After cleaning, URLhaus lists have to be updated by the reporters; there is no promise of a time. We do not know the site's contact. If you own it, contact abuse.ch through their site after the files are gone.

Keep a computer out of this kind of chain

Every report we read starts with a file a person chose to run. That is both the problem and the defence.

Do

  • Get Minecraft only from minecraft.net and the Microsoft Store, and mods from their makers' own pages or well known mod sites.
  • Treat a free cheat client as an attack on your account, whatever the video or the page says.
  • Keep Windows and Microsoft Defender updated; the offline scan uses the latest definitions.
  • Use a password manager and two step sign in, so one stolen password is not enough.
  • Give a child a separate user account on the family computer, without access to your files or logins.
  • Show file endings in File Explorer so a .jar posing as a mod is visible.

Don't

  • Do not download .jar files from sites that promise free versions of paid or banned game advantages.
  • Do not turn off your antivirus because a download page tells you the alert is false.
  • Do not change your passwords on the computer you suspect.
  • Do not rely on a quiet scan to say you are safe.
  • Do not trust a mod because its name matches a well known one.

Questions about niggersmp.net (SilentNet, Minecraft client .jar files)

What is niggersmp.net?

It is a website that presents itself as a place for free Minecraft cheat clients and mods. The abuse.ch project URLhaus lists four of its .jar downloads (Radium_Client.jar, krypton.jar, 4E_Client.jar and Zyphers_Rig_Mod.jar) as malware, all tagged SilentNet and all added on 10 October 2026.

The domain was registered on 5 April 2026. It is not a program on your computer. We did not download the files, so what they contain is not confirmed by us.

Is niggersmp.net safe to open or download from?

Do not download from it. Four of its files are reported as malware and were still marked online when we checked.

Our own plain request to the home page got an ordinary answer with status 200, but that proves nothing: a download page can look normal while the files are the problem, and the site is behind Cloudflare, which can show different visitors different things. The rating comes from the URLhaus reports, not from our visit.

What does the SilentNet tag mean?

SilentNet is a label on the abuse.ch sample site MalwareBazaar for Java malware aimed at Minecraft. One entry we read is a fake build of a known Minecraft client that steals the Minecraft session and relaunches as a hidden process.

We did not find a full analysis from a large security vendor, so treat it as a researcher label. We cannot say that the four files here behave the same way, because we did not open them.

I downloaded and ran one of these .jar files. What now?

Disconnect the computer from the network. From another device, change the password of your email first, then your Microsoft account, Discord, banking and crypto, and sign out of every device.

Then run a Microsoft Defender Offline scan on the computer, remove the file and anything that starts with the system that you did not make, and reset the system if you are not sure. Restore documents by hand, not programs.

I only saw niggersmp.net in a log or a warning. Am I infected?

Not by that alone. The name in a firewall log, a DNS log or a browser warning means a device asked for it, and a person may have clicked a link. It does not mean a file ran.

Find the device, check Downloads and the Minecraft mods folder for the four file names, look at Protection history in Windows Security, and run a scan. If you find none of the files, nothing on this page says you were hit, but a quiet check never fully clears a computer.

Can Minecraft cheat clients steal my account?

Yes, that is the point of many fake ones. Check Point Research described fake Minecraft cheat tools in 2025 that used a Java first stage, a Java stealer and a .NET stealer stage, and a MalwareBazaar entry describes a SilentNet-labelled fake client stealing the Minecraft session.

A stolen session or login lets someone act as you. Cheats are also against the rules of most servers, so the safe choice is not to use a client from an unknown site.

Does this affect Mac, Linux, iPhone or Android?

A .jar file runs wherever Java runs, so a Mac or Linux computer with Minecraft: Java Edition could run it. We do not know whether these four files contain code that works there, and no source we read says so.

An iPhone, an Android phone and the console editions do not run these files in the normal way, and no source mentions them. If you ran a file on a Mac, treat it as exposed and change passwords from another device.

Will resetting the system remove it, and are my accounts safe afterwards?

A reset removes apps and settings, which is the answer that does not depend on finding every piece. Microsoft says you can keep your personal files or remove everything. It does not undo what was already taken.

Passwords, sessions and wallet phrases that a stealer saw stay exposed until you change them from another device and turn on two step sign in. Restore documents by hand and install Minecraft again from the official launcher.

Why would a site like this hand out malware?

We do not know the motive or the owner of this site, and no source tells us. For the type, the reports describe a simple trade: players want free cheats, and a file that looks like a cheat is an easy way to get an account, a wallet or a login.

The site may also be hacked or careless rather than built for it. Either way, the files are reported, and the safe choice is to stay away.

Will Fortect remove niggersmp.net?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For niggersmp.net, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove Quasar virus

Quasar - a Remote Access Tool that has its legitimate and malicious uses Quasar virus is a Remote Access Trojan (RAT) that is often abused by cybercriminals to take remoteTrojansHigh riskJake Doevan ·

Remove H1B scam: how fake H-1B job offers and visa fee demands work, and what to do

An H1B scam is a fake job or visa offer that promises H-1B sponsorship and then asks the worker to pay a fee, send identity papers or both. A real employer pays the H-1B filing costs, so stop paying, check the...TRHigh riskUgnius Kiguolis ·

Remove armoniamiddleeast.ae: a site that served fake Chrome installers for Windows, and what to do

armoniamiddleeast.ae is a website that URLhaus lists for three Windows malware downloads named ChromeSetup.exe, Chrome.exe and google.exe, reported on 24 September 2026. They pretend to be Google Chrome installers....TRHigh riskUgnius Kiguolis ·

Remove andbake.cam: a server that handed out files tagged XWorm, and what to do if a loader on your Windows PC fetched them

andbake.cam is a web address that URLhaus lists four times, on 7 October 2026, for files tagged xworm, and two of them are PNG pictures tagged stego, meaning code hidden inside an image. XWorm is a remote access...TRHigh riskUgnius Kiguolis ·

Questions and experiences: niggersmp.net (SilentNet, Minecraft client .jar files)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,458 members already hereReading, writing, commenting and voting. 0 verified · 183 joined this year