Backdoors & malware
Know what a plugin really does
Malicious plugins look normal until someone types the right phrase. PluginDoctor reads every class for the behaviour that matters: operator grants, remote code loading, outbound connections, token theft and file deletion.
- Hidden commands and chat triggers that grant operator
- Code downloaded and run after install
- Outbound connections, file wipes and credential theft
> plugindoctor scan AuctionPlus-4.2.jar Decompiling 214 classes… [ OK ] file access plugins/AuctionPlus only [ OK ] outbound traffic api.auctionplus.example (declared) [HIGH] u/Loader URLClassLoader → remote host [CRIT] ChatListener setOp(true) on hidden chat phrase 1 critical, 2 high. Full report: plugindoctor.gg/r/9F2A