MINECRAFTHUB.IO
Safety

Is Modrinth Safe to Download Mods From

A dated look at what Modrinth says it reviews, the malicious mod it disclosed in May 2024, the limits of its checks and the habits its own pages point to.

MinecraftHub editorial cover showing a lime block with a tick in a crate beside a red block marked with a cross, joined by a gold chest and an arrow

Published Updated Checked

Modrinth is a platform that hosts user-made Java Edition mods, plugins, data packs, shaders, resource packs and modpacks. Is Modrinth safe? The record gives dated facts, not a verdict. Modrinth says its moderators review submitted projects against its rules, and that an in-house malware scanner can send suspicious code to a technical moderator. It took down a malicious mod called "Windows Borderless" on 6 May 2024 and disclosed it on 7 May 2024. No platform can promise every file is clean.

We did not scan or test any file. This page reports what the platform publishes about its own checks and what has gone wrong in public. Facts were read on 2 October 2026.

What Modrinth says it checks

Modrinth's Help Center page on review times (dated 28 August 2026) says its content moderators review all submitted projects to confirm they comply with Modrinth's Rules and Terms of Use. It adds that an in-house malware scanning tool may detect suspicious traces in a project's code, which sends the code to a technical moderator for manual review.

The same page says mods, plugins and especially modpacks take longer because they are harder to review. Modrinth aims for 24 to 48 hours per project and 72 to 96 hours for modpacks, but warns that delays are currently running to two to four weeks on average, sometimes longer.

Modrinth's Content Rules (last modified 13 August 2026) bar projects designed to upload data to a remote server without clear disclosure, and bar impersonation. They also require a description that says what the project does and any critical information a user must know before downloading. Modrinth's About page (15 October 2025) says most of its code is public under the GNU Affero General Public License, version 3, for anyone to audit.

What has gone wrong

The only incident in the sources read is the "Windows Borderless" disclosure. Modrinth rates its exposure as low and the malware severity as medium.

Timeline of the Windows Borderless incident as Modrinth's disclosure of 7 May 2024 states it
Date (2024)What happenedScale as statedSource
29 to 30 AprilProject submitted with one clean file, then approved by moderatorsOne file, no malwareModrinth News, 7 May 2024
2 MayA new release with malware is published; it sent identifying machine information to a Discord webhookEarly malicious releaseModrinth News, 7 May 2024
4 to 6 MayMore releases uploaded, all containing credential and token stealersFive affected files listedModrinth News, 7 May 2024
6 MayA user reports the mod; moderators decompile it, find malicious code and remove the project and other projects by the same usersRemoved within minutes of investigation, per ModrinthModrinth News, 7 May 2024
7 MayModrinth publishes the disclosure and a detection toolAbout 372 distinct IPs downloaded affected files; one Discord login alleged stolen; none in Modrinth modpacksModrinth News, 7 May 2024

Modrinth said the mod harvested data from Chromium-based browsers and Discord, which may include login tokens, stored passwords and banking details. It affected Windows users who ran the mod. Modrinth also said it was building a web API so launchers can check downloaded files against a known-malware database, working with law enforcement, and investigating sandboxing or algorithmic detection of malware patterns in Java software. The disclosure does not say whether any of that has shipped.

What the checks do not cover

The incident shows the limit. Modrinth approved the project with a clean file on 30 April, and the malicious releases came days later. According to the timeline, the takedown followed a user report. Modrinth's own review-times page says queues run behind and that mods, plugins and modpacks are harder to review.

The Content Rules also say some listed metadata expectations are not enforced as strictly, and the Security Notice (dated 2026-03) covers how to report vulnerabilities in Modrinth's own repositories, not malicious mod files. In May 2024 Modrinth described sandboxing and pattern detection as work it was investigating. Its pages do not promise that every file is clean, and neither can we.

What you can do before you install

  • Read the project description. Modrinth's rules require it to say what the project does and any critical information before you download.
  • Match the exact project name. Modrinth's disclosure stressed that mods called "Borderless Mining", "Borderless" and "Borderless Mining Reworked" are not the malicious one.
  • Report a problem. Modrinth says to use the Report button on any project, version or user page, or email [email protected].
  • If you ran the malicious mod, Modrinth says to delete it, change all your passwords and watch your bank accounts and cards. It also offers an open-source detection tool that scans a mods folder.
  • Use Modrinth's own tools for installs where you can. Our guides cover the Modrinth App, installing mods on Java Edition and installing a modpack. Modrinth describes its App as in public beta.

Sources

  1. 1.Project Review Times, Modrinth Help Center (support.modrinth.com, 28 August 2026)
  2. 2.Malware Discovery Disclosure, Windows Borderless mod (modrinth.com, 7 May 2024)
  3. 3.Content Rules (modrinth.com, last modified 13 August 2026)
  4. 4.About Modrinth, Modrinth Help Center (support.modrinth.com, 15 October 2025)
  5. 5.Security Notice (modrinth.com, dated 2026-03)

Related guides and articles.