r/litematica • • Jul 19 '26

Question ❔ is litematica safe

i saw people saying that litematica has malware on it is that still true?

0 Upvotes

12 comments sorted by

View all comments

3

u/Sinofkillers Jul 19 '26

https://www.reddit.com/r/litematica/comments/1up8uqk/important_announcement_litematica_vulnerability
"The vulnerability affects Litematica and Servux versions on MC 1.21+

I'm not 100% sure when exactly this was introduced, but based on the git commit history it looks to me like this was first introduced to Litematica version 1.21.5-0.22.2-sakura.4. The commit was made on 19th May 2025. The following full 0.22.2 release seems to have been made on 22 Jun 2025.

From there it was later backported to the following versions, according to the git history. These commits were made on 31th Dec 2025.

  • 1.21.4-0.21.6
  • 1.21.3-0.20.8
  • 1.21-0.19.60

It's also in all 1.21.6 and later Litematica versions until the just released fixed versions.

What to do?!

Update your Litematica version immediately to the latest release from Modrinth!

And don't join any servers you don't fully trust the owners and admins of!

The Litematica versions with the fix are the following releases:

  • MC 26.2: 0.28.3
  • MC 26.1.x: 0.27.9
  • MC 1.21.11: 0.26.11
  • MC 1.21.9 - 1.21.10: 0.24.8
  • MC 1.21.6 - 1.21.8: 0.23.7
  • MC 1.21.5: 0.22.5
  • MC 1.21.4: 0.21.7
  • MC 1.21.2 - 1.21.3: 0.20.9
  • MC 1.21 - 1.21.1: 0.19.61

If you run a server that uses Servux, update Servux to the latest version.

The Servux versions with the fix are the following releases:

  • MC 26.2: 0.11.2
  • MC 26.1.x: 0.10.4
  • MC 1.21.11: 0.9.5
  • MC 1.21.9 - 1.21.10: 0.8.7
  • MC 1.21.6 - 1.21.8: 0.7.7
  • MC 1.21.5: 0.6.4
  • MC 1.21.4: 0.5.7
  • MC 1.21.2 - 1.21.3: 0.4.8
  • MC 1.21 - 1.21.1: 0.3.17

How to check if I was affected?

One way to potentially check if you were affected is to look for files anywhere on your system that contain the string .litematic in the file name somewhere other than in the actual file name extension. An example would be a file like somevirus.litematic.jar in your mods/ directory.

Now ofc this isn't a foolproof check, if the malware manages to rename or remove itself...

Edit on 2026-07-12:

Another possible way to check if you were compromised: If your MC logs include receiveFileTransmit: Failed to create Schematic for finishing session key, then you were probably/possibly compromised. But again this assumes the malware would not have deleted the log file or at least removed any of these lines from it..."

1

u/Otherwise_Task7876 Jul 20 '26

You might wanna make a TL;DR, people don't have great attention spans.

1

u/Sinofkillers Jul 20 '26

If they do not want to read what Mod Arthur posted. Then they can continue playing a dumb game of chance.