Malicious Code & Pirated (Nulled) Plugins

Security & DDoS Reviewed September 6, 2026 1 min read

A paid plugin offered for free on a forum is not a bargain, it is bait. Cracked builds are the most common way a Minecraft server gets compromised, and the damage is usually irreversible.

What you are seeing

  • Operator permissions appear for accounts you never granted them to.
  • Files or worlds disappear without anyone running a command.
  • The server generates outbound traffic or CPU load that does not match what is running.

Why it happens

Plugins from unofficial forums and nulled repositories are frequently modified before they are republished. The usual payloads are a backdoor that phones home, a force-OP routine that grants the author operator on your server, and in the worst cases a script that wipes the disk.

What to do

  1. Install only from the official source

    The plugin author's own page, SpigotMC, Modrinth or the developer's repository. If a paid plugin is being given away, the copy has been modified.

  2. If you suspect an infection, rebuild rather than clean

    Start from a fresh installation and reinstall each plugin from its official source. A backdoor that granted itself operator can re-add itself from anywhere it wrote to.

  3. Rotate everything the server could have leaked

    RCON password, database passwords and any API token stored in a plugin configuration.

Worth knowing

Under Article 19 of our Terms, the security of the software you install is yours. Support does not clean infected servers or recover compromised files, and an instance running malware that degrades the node for other customers is suspended immediately.