MINECRAFTHUB.IO
Safety

Is CurseForge Safe to Download Minecraft Mods From

A read of CurseForge's own published checks, the June 2023 malware incident and the May 2026 impersonation warning, with the limits CurseForge itself states and habits it suggests.

MinecraftHub editorial cover showing a red block with a cross on the left, an arrow to a gold chest with a lime tick on the right, standing on dark stone ground

Published Updated Checked

CurseForge is a mod and modpack hosting platform, and its support pages are signed Overwolf Support. It says every uploaded file goes through automated tests and some go to manual review. In June 2023 a targeted malware attack put infected mod files on the platform, and CurseForge reports they were downloaded about 6,500 times. In May 2026 it warned that scammers pose as community members to push fake modpacks from outside the platform. No platform can promise that every file is clean.

We did not scan or test any file. This page reports what the platform publishes about its own checks and what has gone wrong in public. Facts were read on 2 October 2026.

What CurseForge says it checks

CurseForge's incident report of 19 June 2023 describes a three-layer moderation process. Layer 1 is automated: it says all uploaded files undergo over a dozen automatic tests, including several anti-virus scans, file structure scans and compliance tests. Layer 2 is manual: project pages are reviewed when a project is created or updated, and a file that triggers suspicion is flagged for a security expert at Overwolf, who runs extra tests and, when relevant, live-tests the file in the game. Layer 3 is community reporting, including a "Report a Mod" feature open to players and modders.

The moderation policies page, modified 8 September 2026, repeats the shape of this: files go through processors, automated checks and manual review, and the page says moderation is done as well as the team can manage. The known issues page, modified 24 September 2026, adds that a Minecraft file can be sent to a Malware Processor, which can take a few days depending on queue size. A May 2026 post says CurseForge scans all files you download directly through its app or website.

What has gone wrong

Incidents on record in the pages we read, with scale as each page states it
DateWhat happenedScale as statedSource
7 June 2023A malicious actor made several author accounts and uploaded infected mod files. A device belonging to a creator at Lunar Pixel Studios was also infected, which let the attacker upload infected files to that studio's mod projects.Infected files downloaded about 6,500 times during the incident, according to CurseForgeCurseForge incident report, 19 June 2023
Mid-April to June 2023Reports of malicious mod and plugin files go back to mid-April. The investigators' guide says downloads from CurseForge or the Bukkit plugin repository made from February to June 2023 should be treated as potentially malicious.No download count givenfractureiser users guide (GitHub)
Page dated 06/11/2023CurseForge's detection tool page lists affected projects: 8 infected and later fixed, and 54 taken down permanently (15 mods, 3 modpacks, 36 Bukkit plugins).Per-project counts of non-unique downloads at time of detectionCurseForge support, June 2023 detection tool page
14 May 2026CurseForge warned of fake modpacks sent over Discord by people impersonating community members. One reported case was a small ZIP holding a file named EchoVoiceBeta-1.0-SNAPSHOT.jar.One player report; the player submitted the file to VirusTotal before installing itCurseForge post, 14 May 2026

On the 2023 attack, CurseForge says the malware was made to infect only Minecraft mod files and evaded commercial anti-virus software. It says the community spotted the attack first, and that within 10 hours it blocked the attacker's accounts, removed their files, built detection tools, scanned its whole database and added new automated tests. Its support page says the malware affected Windows and Linux, not Mac. The investigators' guide lists what the later stages tried to do, including stealing browser cookies, Discord credentials and Microsoft and Minecraft logins. It also states that CurseForge itself was not compromised, only individual users, and that with uploads back online, copycat malware was possible.

The 2026 warning is a different pattern. CurseForge says those attacks do not come through CurseForge itself. Scammers use Discord messages and social engineering to get players to install malicious files from outside the platform.

What the checks do not cover

CurseForge's own pages state three limits. First, files that never pass through its pipeline: its support page says modpacks shared manually can be changed by their creators or anyone who handled the file before you, and that CurseForge cannot verify or guarantee their safety. The May 2026 post likewise says it cannot scan modpack files sent by friends and imported into the app.

Second, new malware. CurseForge's 2023 report says the attack used a new type of malware built to evade all commercial anti-virus software, which is why it added new tests afterwards. Third, impersonation. Its known issues page says Overwolf and CurseForge employees never ask for information in direct messages, and that a real staff member shows an Admin or Support tag on their user page. Moderation itself is described as a good-faith effort, not a promise.

What you can do

Each habit below is one CurseForge states in its May 2026 post or support pages, except the report route, which comes from its moderation page.

  • Install modpacks through CurseForge project pages or the app, and use the app to manage imports and read its warnings. Our guide to installing a modpack covers the steps.
  • Avoid ZIP files sent through Discord direct messages, even from someone you know.
  • On an import warning, choose "CurseForge Files Only", or cancel and get the pack from its project page.
  • Check imported packs before launching them, and treat unfamiliar JAR files, odd filenames or overrides unrelated to the pack as a reason to stop.
  • Scan suspicious files with a tool such as VirusTotal, which CurseForge names.
  • Do not rush into an install because another user is pressuring you, or says a download is required to join them.
  • Report a project that passed moderation with the report function on the website, or open a support ticket.

For mods rather than packs, our Java mod install guide shows where files go, and if the app will not start, see fix CurseForge not launching Minecraft. Anyone who thinks they ran a file from the 2023 attack should follow CurseForge's detection tool page and the investigators' guide, since those describe the Windows and Linux checks.

Sources

  1. 1.Safeguarding our community: CurseForge Fighting Malware Incident Report (blog.curseforge.com, 19 June 2023)
  2. 2.Moderation Policies (CurseForge support, modified 8 September 2026)
  3. 3.Stay Safe: How To Spot Suspicious Modpacks And Files (blog.curseforge.com, 14 May 2026)
  4. 4.June 2023 Infected mods detection tool (CurseForge support, modified 8 April 2024)
  5. 5.fractureiser users guide (trigram-mrp on GitHub, undated)
  6. 6.Sharing Modpacks/Custom Profiles (CurseForge support, modified 7 July 2026)
  7. 7.CurseForge Known Issues (CurseForge support, modified 24 September 2026)

Related guides and articles.