Modrinth is a platform that hosts user-made Java Edition mods, plugins, data packs, shaders, resource packs and modpacks. Is Modrinth safe? The record gives dated facts, not a verdict. Modrinth says its moderators review submitted projects against its rules, and that an in-house malware scanner can send suspicious code to a technical moderator. It took down a malicious mod called "Windows Borderless" on 6 May 2024 and disclosed it on 7 May 2024. No platform can promise every file is clean.
We did not scan or test any file. This page reports what the platform publishes about its own checks and what has gone wrong in public. Facts were read on 2 October 2026.
What Modrinth says it checks
Modrinth's Help Center page on review times (dated 28 August 2026) says its content moderators review all submitted projects to confirm they comply with Modrinth's Rules and Terms of Use. It adds that an in-house malware scanning tool may detect suspicious traces in a project's code, which sends the code to a technical moderator for manual review.
The same page says mods, plugins and especially modpacks take longer because they are harder to review. Modrinth aims for 24 to 48 hours per project and 72 to 96 hours for modpacks, but warns that delays are currently running to two to four weeks on average, sometimes longer.
Modrinth's Content Rules (last modified 13 August 2026) bar projects designed to upload data to a remote server without clear disclosure, and bar impersonation. They also require a description that says what the project does and any critical information a user must know before downloading. Modrinth's About page (15 October 2025) says most of its code is public under the GNU Affero General Public License, version 3, for anyone to audit.
What has gone wrong
The only incident in the sources read is the "Windows Borderless" disclosure. Modrinth rates its exposure as low and the malware severity as medium.
| Date (2024) | What happened | Scale as stated | Source |
|---|---|---|---|
| 29 to 30 April | Project submitted with one clean file, then approved by moderators | One file, no malware | Modrinth News, 7 May 2024 |
| 2 May | A new release with malware is published; it sent identifying machine information to a Discord webhook | Early malicious release | Modrinth News, 7 May 2024 |
| 4 to 6 May | More releases uploaded, all containing credential and token stealers | Five affected files listed | Modrinth News, 7 May 2024 |
| 6 May | A user reports the mod; moderators decompile it, find malicious code and remove the project and other projects by the same users | Removed within minutes of investigation, per Modrinth | Modrinth News, 7 May 2024 |
| 7 May | Modrinth publishes the disclosure and a detection tool | About 372 distinct IPs downloaded affected files; one Discord login alleged stolen; none in Modrinth modpacks | Modrinth News, 7 May 2024 |
Modrinth said the mod harvested data from Chromium-based browsers and Discord, which may include login tokens, stored passwords and banking details. It affected Windows users who ran the mod. Modrinth also said it was building a web API so launchers can check downloaded files against a known-malware database, working with law enforcement, and investigating sandboxing or algorithmic detection of malware patterns in Java software. The disclosure does not say whether any of that has shipped.
What the checks do not cover
The incident shows the limit. Modrinth approved the project with a clean file on 30 April, and the malicious releases came days later. According to the timeline, the takedown followed a user report. Modrinth's own review-times page says queues run behind and that mods, plugins and modpacks are harder to review.
The Content Rules also say some listed metadata expectations are not enforced as strictly, and the Security Notice (dated 2026-03) covers how to report vulnerabilities in Modrinth's own repositories, not malicious mod files. In May 2024 Modrinth described sandboxing and pattern detection as work it was investigating. Its pages do not promise that every file is clean, and neither can we.
What you can do before you install
- Read the project description. Modrinth's rules require it to say what the project does and any critical information before you download.
- Match the exact project name. Modrinth's disclosure stressed that mods called "Borderless Mining", "Borderless" and "Borderless Mining Reworked" are not the malicious one.
- Report a problem. Modrinth says to use the Report button on any project, version or user page, or email [email protected].
- If you ran the malicious mod, Modrinth says to delete it, change all your passwords and watch your bank accounts and cards. It also offers an open-source detection tool that scans a mods folder.
- Use Modrinth's own tools for installs where you can. Our guides cover the Modrinth App, installing mods on Java Edition and installing a modpack. Modrinth describes its App as in public beta.
Sources
- 1.Project Review Times, Modrinth Help Center (support.modrinth.com, 28 August 2026)
- 2.Malware Discovery Disclosure, Windows Borderless mod (modrinth.com, 7 May 2024)
- 3.Content Rules (modrinth.com, last modified 13 August 2026)
- 4.About Modrinth, Modrinth Help Center (support.modrinth.com, 15 October 2025)
- 5.Security Notice (modrinth.com, dated 2026-03)
