A counterfeit Minecraft optimization mod posing as a companion to the legitimate Lithium project has been used to infect Windows users with Myth Stealer 3.2-FIX, an information stealer and remote-access trojan. The malicious Java archive retains 12 working optimization modules to appear credible but embeds a concealed thirteenth loader that fingerprints the host and launches a multi-stage payload chain, including a Node.js-based second stage named DiscordNitroGenerator.exe.
Myth Stealer can collect browser credentials, cookies, history, system and chat data, clipboard contents, local files, screenshots, and webcam captures, while enabling persistence, remote command execution, and disruptive actions. The campaign used Dropbox to host second-stage payloads, Discord webhooks for reporting and exfiltration, and infrastructure including 146[.]19[.]191[.]11 and ays[.]gamepazarin[.]com; the analyzed command-and-control server was offline at the time of reporting. Analyst devmihaylov reported that initial samples obtained from a commodity-stealer buyer had no VirusTotal detections.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
A counterfeit Minecraft optimization mod masquerading as a companion to the Lithium project was identified delivering a multi-stage Myth Stealer 3.2-FIX infection chain to Windows users. The malware steals browser credentials and cookies, system and user data, screenshots and webcam captures, and provides remote execution, persistence, and disruptive functions; the analyzed C2 infrastructure was offline when reported.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.