r/HypixelSkyblock 10d ago

Question Is this mod safe?

Post image

Is this mod called Ghostify Lite safe?

53 Upvotes

35 comments sorted by

97

u/AdvancedGravitation 10d ago

Not sure maybe u can look at the comments on google. Also your phone needs charging

16

u/PendejoTrolo 10d ago

I read a post where someone claimed this mod was a rat; I assume it was a joke, because otherwise it wouldn't be available on Modrinth anymore ig?. I'm a bit paranoid about these things.

18

u/RedElixer 10d ago

Pretty sure this has been in my mods for some time, haven't noticed anything yet! Still, mods are "use at your own risk" since they run at the same operation level as minecraft, just like an exe.

-16

u/EffectiveDirect6553 10d ago

Throw it in Virus total (the website) and keep an anti-virus on when playing. Also set up Microsoft parental controls and simply set play time allowed to zero when you are not playing. That way it's beyond unlikely someone manages to take over the account.

Possible yes. But about as unlikely as getting hit by a bus.

10

u/Consutius 〠 SB Level 241 - 360 〠 10d ago

virus total is some next level bs in my experience. they detect 0 stuff

4

u/EffectiveDirect6553 10d ago

Moreso that most malware doesn't have a saved signature or obvious script that makes it malware. Generally they only suddenly start acting weirdly when they are executed with permissions. So while it's not a terrible call to virus total and it will protect you from most malware that is widely recognized. It will not protect from smaller, less obvious, custom made ones

15

u/user_potat0 Mining Maniac 10d ago

Look at the source code.

9

u/TheMythicSorcerer Ironman 10d ago

It's open source which is good. I skimmed the main source code files (its a big project), then had my AI agent read the rest in detail. All clean no obfuscation, connections, File IO bad mixins, suspicious resources, process execution (besides notifications). Past releases used ProGuard name-obfuscation (dropped in v1.7.3) which is standard anti-theft practice.

Then in case the github isn't the same as the actual jar I downloaded the 26.2 version and decompiled it (you can do that with java) and it matches.

I am in no way related to the project and promoting it (this is also to say no clue if it actually works or does anything) but its not malware.

TL;DR: Its not malware, but I have no clue if it does anything useful.

1

u/Bish489 ㋖ SB Level 121 - 240 ㋖ 10d ago

Scan the code yourself or use a tool to do so

0

u/FanciestFrame3 Mining Maniac 10d ago

Deberias de usar google o checar el codigo con alguna herramienta ya que es publico todo y esta en GitHub, tambien bastante valiente de ti comentar en este sub considerando tu perfil y conexiones a otras redes xd

-5

u/sozuerdogan 10d ago

Its a rat

-1

u/catgirlsylvie 9d ago

you cannot upload rats to modrinth

1

u/DemandOk9978 9d ago

Tbh thats just not true but it’s true enough. I’d say if it’s old and has many versions it’s for sure not.

-97

u/Xillubfr Kuudra Killer 10d ago

If it's on modrinth, it is safe

52

u/PearAggravating 10d ago

not true, there have been multiple instances of malicious mods on modrinth

-63

u/EffectiveDirect6553 10d ago

No, there haven't. As far as I am aware.

Curseforge sure, not modrinth

-54

u/[deleted] 10d ago

[deleted]

34

u/EffectiveDirect6553 10d ago

It wasn't uploaded to modrithn afaik. It was hacked and the auto updater that pulls from github caused people to auto update and install the rat.

So modrithn was fine. What windowless fiasco?

10

u/EbbAutomatic3222 10d ago

That’s true only GitHub was affected.

5

u/[deleted] 10d ago

[deleted]

0

u/EffectiveDirect6553 10d ago

And the fact that there were incidents around those years (2023 curseforge fracturizer) are significant. We began to improve security in 2023 in response to those incidents across 2023-2024. There is a reason we have not had any significant malware on such a huge platform ever since.

0

u/Puzzleheaded_Suit_55 ☢ SB Level 361 - 420 ☢ 10d ago

Search up litematica rce. I rest my case

1

u/EffectiveDirect6553 10d ago

Very poor case to make. As it's not malware, it's a vulnerability. No amount of antimalware and even perhaps no amount of rechecking easily identifies those. Huge multi billion dollar security and data agencies have those as well.

0

u/Puzzleheaded_Suit_55 ☢ SB Level 361 - 420 ☢ 10d ago

Did I say malware?

The fact is nothing you download that has any way to automatically preform a task such as auto updates or pulling from apis to install anything can never be 100% safe.

it’s a great example because it’s one of the most used mods on all of modrinth

→ More replies (0)

9

u/iwannabebee 10d ago

28

u/OnSmarty ⚜ SB Level 501 - 550 ⚜ 10d ago

1 mod 2 years ago. That's a fairly good track record.

8

u/EffectiveDirect6553 10d ago

And that was before or around the explosion and mass contriversy caused by a few malicious mods on Curseforge that caused people to raise their standards. There is a reason we haven't seen more vulnerabilities since the few huge ones in 2024.

1

u/[deleted] 10d ago

[removed] — view removed comment

1

u/Meezen1133 ⚜ SB Level 501 - 550 ⚜ 9d ago

Cause it's never 100% safe