Most backdoored game server plugins arrive by one of four routes: a leaked or "nulled" copy of a paid plugin, a lookalike upload pretending to be a popular one, a genuine project whose author account was hijacked, or a developer or helper you gave file access to. The code itself is usually simple - a hidden chat phrase that grants operator, a web request whose answer is executed as code, a second file dropped somewhere you do not look - and on scripted platforms such as Garry's Mod and FiveM you can find much of it with a text search. The defence is mostly about where files come from and who can write to your server, and only partly about inspecting what you downloaded.
This post is the attacker's side of the picture: how the bad code gets in and what it looks like when it is there. The everyday routine of installing mods safely - trusted sources, checksums, one change at a time, backups before every install - is in keeping a modded server clean, and it is worth reading alongside this one.
The four routes onto your server#
| Route | How it looks to you | What stops it |
|---|---|---|
| Leaked or nulled plugin | A free copy of something that costs money | Not downloading it |
| Lookalike upload | A familiar name, a different uploader | Checking the author and the project page |
| Compromised author | A normal update from the real project | Delaying updates, watching reports |
| Someone with file access | A "fix" or a "helper" plugin | Limiting who can write files |
The first route is by far the most common. Removing a licence check from a paid plugin means decompiling it and rebuilding it, and whoever does that work has every opportunity to add something. They are also distributing stolen software, which tells you something about their priorities. Leak sites have no reason to give you a clean copy and several reasons not to: an admin backdoor on hundreds of servers is a saleable thing.
The second route relies on you searching rather than navigating. A plugin called "EssentialsX-Fix", a GitHub repository with a near-identical name and a single release, a YouTube video whose description links to a "mirror". The file is plausible, the name is close, and the author is somebody you have never heard of.
The third route is the one that catches careful people, because it comes through the channel you were told to trust. If a well-known mod author's account is taken over, the next "update" from the official project page can carry anything. This has happened on the largest platforms.
The fourth route is people. A developer hired to build a custom feature, a volunteer who "knows how to fix the lag", a former staff member with SFTP access that nobody revoked. They do not need to sneak a backdoor in; they can just put it there.
What the payload usually does#
Backdoors on game servers are rarely sophisticated. They do not need to be, because most servers have no monitoring and most owners never read the code they run.
| Payload | Why the attacker wants it |
|---|---|
| Secret chat phrase or command grants admin | Control of your server whenever they join |
| Remote code loader | They can change behaviour later without touching your files |
| Credential collector | RCON, database and panel passwords from config files |
| Dropper | Writes more plugins or files, survives removal of the first |
| Crypto miner | Uses your CPU allocation for their profit |
| Player-facing abuse | Broadcasts, item spawns, server-wide griefing on demand |
| Client infection | On games that send content to players, attacks your players' PCs |
The remote loader is the one to be most worried about, because it means the backdoor you find today may not be the behaviour you get tomorrow. The code on disk is small and boring - fetch a URL, run what comes back - and everything interesting lives on the attacker's server, where you cannot read it.
The credential collector matters because of what plugin config files contain. Database passwords for plugins that use MySQL, web panel tokens, webhook URLs, sometimes the RCON password. Once those are taken, removing the plugin does not end the problem.
A real supply-chain case: fractureiser#
In June 2023, Minecraft mod and plugin users found a malware campaign that was later named fractureiser. Attackers gained access to accounts on CurseForge and on dev.bukkit.org and uploaded infected versions of existing projects. People who downloaded those files from the official platforms got a jar with a small injected loader. When the mod or plugin ran, the loader fetched further stages from the internet; the later stages stole credentials - browser cookies, Discord tokens, Minecraft and Microsoft account sessions - and tried to infect other .jar files on the same machine.
Several lessons came out of it that apply to any game:
- "Official source" lowers the risk; it does not remove it. The files came from exactly where the guides tell you to go.
- Brand-new uploads are the risky window. The infected versions were live for a limited time before they were noticed and removed. Servers that waited a few days before applying mod updates were never exposed.
- A jar can infect other jars. Once anything malicious runs, every executable file the server user can write is suspect, which is why cleaning by hand is a poor strategy and restoring from a known-good backup is a good one.
- The community response was fast. Detection tools and write-ups appeared within days. Following the platform's announcements is worth more than any scanner you run yourself.
The practical defence for a server is cheap: do not update mods on the day they are released unless the update fixes something you need, keep the previous working file, and take a backup before every update.
Garry's Mod and FiveM: code you can actually read#
Scripted platforms have one big advantage: most server code is plain Lua or JavaScript, so you can search it. Backdoors on these platforms are common for the same reason - leaked addons and resources circulate widely - and they follow recognisable patterns.
On Garry's Mod, the classic backdoor fetches text from a URL and runs it with RunString or CompileString, or adds a hidden net message that runs a console command for whoever sends it. Searching the addons folder for the functions that execute dynamic code finds most of them:
$ cd garrysmod/addons$ grep -rn --include='*.lua' -E 'RunString|CompileString|CompileFile' .$ grep -rn --include='*.lua' -E 'http\.Fetch|http\.Post|HTTP\(' .$ grep -rn --include='*.lua' -E 'game\.ConsoleCommand|RunConsoleCommand' .$ grep -rln --include='*.lua' -E '\\x[0-9a-fA-F]{2}.*\\x[0-9a-fA-F]{2}' .Hits are not proof of guilt - plenty of legitimate addons fetch updates or run console commands - but each one should make sense for what the addon claims to do. A prop-spawning addon that fetches a URL and passes the result to RunString does not have an innocent explanation. The last search finds long runs of hex-escaped characters, which is a common way to hide a URL or a function name from a casual reader. Garry's Mod workshop and FastDL covers where server addons actually live.
On FiveM, the equivalent pattern is PerformHttpRequest with the response passed to load, often wrapped as assert(load(...))(), hidden inside an otherwise ordinary resource. In 2023 a widely discussed family of these backdoors, known as Cipher, spread mainly through leaked resources and gave its operators remote control of infected servers.
$ cd resources$ grep -rn --include='*.lua' -E 'PerformHttpRequest' .$ grep -rn --include='*.lua' -E '(^|[^a-zA-Z_])load\(' .$ grep -rn --include='*.js' -E 'eval\(|new Function\(|https?\.get\(' .$ grep -rln -E '\\x[0-9a-fA-F]{2}.*\\x[0-9a-fA-F]{2}' .Look at every fxmanifest.lua too. A resource that lists a server script you do not recognise, or a file with a random name buried in a subfolder, deserves a read. Escrowed (encrypted) resources from the official asset system cannot be read, which is one of the trade-offs of buying them - but they come from a known seller through Cfx.re, which is a provenance you can check. FiveM escrow and asset licensing goes into that system.
Minecraft and Unity games: compiled code#
Bukkit plugins, Forge and Fabric mods and BepInEx plugins are compiled. You cannot grep the source, and obfuscation is normal for paid plugins, so a full review is not realistic for most owners. What you can do is narrower:
- Unpack and search for strings. A jar is a zip file; unpacked class files still contain readable strings such as URLs and class names. The commands are in the mod safety post.
- Look for the methods backdoors need. In Java,
URLClassLoader,defineClass,Runtime.getRuntime().execandProcessBuilderhave legitimate uses but are rare in, say, a chat-formatting plugin. A plugin listening to chat events and callingsetOpis a red flag in any decompiler. - Run a community scanner. For Minecraft there are open-source scanners that look for known malware signatures in plugin folders; MCAntiMalware is one widely used example. Treat a clean result as "not a known sample", not as "safe".
- Watch behaviour. Outbound connections from the server process to addresses you do not recognise, operators you did not add, and CPU use with nobody online are the signs that matter.
On Unity games with BepInEx, such as Valheim, the same applies to .dll files in BepInEx/plugins: get them from Thunderstore, Nexus Mods or the author's own repository, and check the author on the project page. Valheim mods with BepInEx covers the layout.
Checking that a source is what it claims to be#
Provenance is the defence that works across every platform. A few checks catch most fakes in under a minute:
- Navigate, do not search. Go to the plugin platform and open the project page from there, or follow the link from the author's own site or GitHub profile.
- Compare the uploader with the author. On SpigotMC, Hangar, Modrinth, CurseForge, Thunderstore and the Workshop, the uploader is shown on the page. A popular plugin re-uploaded by a different account is a fake until proven otherwise.
- Look at the history. A real project has versions going back months or years, issues, and a changelog. A repository created last week with one release and no source is not where that plugin lives.
- Check release assets against source. On GitHub, a release binary is uploaded separately from the code. An account that publishes clean source and a modified jar is possible; downloading from the project's normal channel is safer than from a fork.
- Read the comments on recent updates. Reports of strange behaviour usually appear there first.
- Wait a few days on updates you do not need. The fractureiser lesson in one line.
Write down where every file came from. A text file in the server root with each mod, version, source URL and date costs a minute per install and makes every later investigation faster.
Hired developers, helpers and file access#
Giving someone write access to your server files is giving them the ability to run code on your server. That is fine when it is intentional; most backdoors from people happen because it was not thought through.
- Give file access to as few people as possible. On the panel, a moderator needs console access, not files. Subuser permissions let you grant console only, files only, or both, without sharing your account - see subusers and least privilege.
- Use time-boxed access for contractors. Access that expires on its own is access you cannot forget to remove.
- Ask for source, and diff what they deliver. For scripted platforms, compare the folder before and after their work. For compiled plugins, ask for the source and the build instructions as part of the job.
- Read the server's activity log after the work is done, and compare file modification times with the dates they were working.
- Rotate passwords afterwards. Database, RCON and any web tokens the developer could read in config files.
None of this means hired developers are untrustworthy. It means trust should be specific and temporary, and a backup taken before they start makes undoing their work possible.
What to do when you find one#
- Stop the server and take a backup of its current state for evidence, then do not run it again as-is.
- Identify the source. Which file, which download, which date. Your install notes help here.
- Rotate every secret the server could read: RCON, admin passwords, database passwords, webhook URLs, tokens in configs. If you reused any of them elsewhere, change them there too.
- Restore from a backup taken before that file arrived, then re-add mods from their official sources, one at a time.
- Check admin lists, scheduled tasks and startup settings for anything you did not set.
- Tell your players if the game sends content to clients, so they can check their own machines.
The full sequence for a confirmed compromise is in what to do when your server is hacked. The important point here: cleaning by deleting one file is not enough when the code could have written others.
On RE:NODE, mods and plugins go up through the file manager or SFTP, or come in through the game's own workshop support, and nothing is inspected on the way in - what runs on your server is your decision. What the panel gives you is the recovery side: backup slots on every plan, stored off the machine they protect, restored with one button, and lockable so a known-good backup is not rotated away while you investigate.
FAQ#
Are plugins from SpigotMC, Modrinth or the Workshop always safe?
They are much safer than anything else, and they are not guaranteed. Platforms do some review and remove malware once reported, but compromised author accounts and new malicious uploads have both happened. Prefer established projects and wait a few days on updates.
Can an antivirus scan find a backdoored plugin?
Rarely. Java, .NET and Lua backdoors do not look like Windows malware, so general-purpose antivirus often reports them clean. Community scanners for specific platforms do better against known samples, and provenance does better still.
Is it safe to use a leaked plugin if I check the code?
No. Paid plugins are usually obfuscated, so you cannot check them properly, and leaked copies are exactly where backdoors are concentrated. It is also somebody else's paid work.
Can a server mod infect my players?
On games that send content or scripts to clients, yes. Garry's Mod and FiveM send client-side scripts, and Minecraft mod packs install code on every player's machine. A malicious mod there is a risk to your community, not only to your server.
How do I know if a plugin is phoning home?
Search its unpacked files for URLs and check whether each one belongs to the project, and watch for outbound connections from the server process to unknown addresses. Many legitimate plugins check for updates, so judge the destination, not the fact of a connection.




Comments
Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.