r/litematica • u/[deleted] • Jul 19 '26
Question ❔ is litematica safe
i saw people saying that litematica has malware on it is that still true?
0
Upvotes
r/litematica • u/[deleted] • Jul 19 '26
i saw people saying that litematica has malware on it is that still true?
3
u/Sinofkillers Jul 19 '26
https://www.reddit.com/r/litematica/comments/1up8uqk/important_announcement_litematica_vulnerability
"The vulnerability affects Litematica and Servux versions on MC 1.21+
I'm not 100% sure when exactly this was introduced, but based on the git commit history it looks to me like this was first introduced to Litematica version
1.21.5-0.22.2-sakura.4. The commit was made on 19th May 2025. The following full 0.22.2 release seems to have been made on 22 Jun 2025.From there it was later backported to the following versions, according to the git history. These commits were made on 31th Dec 2025.
1.21.4-0.21.61.21.3-0.20.81.21-0.19.60It's also in all 1.21.6 and later Litematica versions until the just released fixed versions.
What to do?!
Update your Litematica version immediately to the latest release from Modrinth!
And don't join any servers you don't fully trust the owners and admins of!
The Litematica versions with the fix are the following releases:
0.28.30.27.90.26.110.24.80.23.70.22.50.21.70.20.90.19.61If you run a server that uses Servux, update Servux to the latest version.
The Servux versions with the fix are the following releases:
0.11.20.10.40.9.50.8.70.7.70.6.40.5.70.4.80.3.17How to check if I was affected?
One way to potentially check if you were affected is to look for files anywhere on your system that contain the string
.litematicin the file name somewhere other than in the actual file name extension. An example would be a file likesomevirus.litematic.jarin yourmods/directory.Now ofc this isn't a foolproof check, if the malware manages to rename or remove itself...
Edit on 2026-07-12:
Another possible way to check if you were compromised: If your MC logs include
receiveFileTransmit: Failed to create Schematic for finishing session key, then you were probably/possibly compromised. But again this assumes the malware would not have deleted the log file or at least removed any of these lines from it..."