Repository files navigation

Jarsec

A Claude Code skill that analyzes Minecraft mods for malware. It does both static analysis (reading the code) and dynamic analysis (actually running the mod in a sandbox) to check for infostealers, RATs, obfuscation, C2 infrastructure, and other nasty stuff.

Install

npx skills add https://github.com/tinywifi/jarsec

What you need

  • Docker (required - the mod never runs on your actual machine)
  • Java (required for decompilation - openjdk-21-jdk or any JDK 17+)
  • Optional extras: unzip, tcpdump, tshark, strace, python3-pip

Decompilers (Vineflower + CFR fallback) are downloaded automatically on first run. The Docker sandbox image can be pre-built or built locally.

Jarsec will check what you have installed and tell you exactly what's missing.

How to use it

Analyze the source code in your current folder

claude
/jarsec

Analyze a local JAR file

claude
/jarsec /path/to/mod.jar

Download and analyze a JAR from a URL

claude
/jarsec https://cdn.modrinth.com/data/.../mod.jar

What it actually checks

Static analysis (4 agents running in parallel):

  • Decompiles JAR bytecode to readable Java source via Vineflower (falls back to CFR)
  • Build configuration for malicious repos, shadow jars, or obfuscation
  • Infostealer signatures (Discord webhooks, token grabbers, session theft)
  • Known Weedhack/majanito malware IOCs
  • Malicious APIs (Runtime.exec, ProcessBuilder, clipboard hijacking, etc.)
  • Persistence mechanisms (startup injection, registry keys, scheduled tasks)
  • Stage-2 droppers (OS fingerprinting, temp file writes, URLClassLoader)
  • Viral propagation (JAR/zip file iteration, self-replication)
  • Network C2 (hardcoded URLs, Telegram bots, blockchain/Ethereum C2)
  • Mixin review (checking if mixins intercept sensitive packets without good reason)
  • Unsafe deserialization (BleedingPipe vectors)
  • Reflection abuse, anti-sandbox checks, JVM instrumentation, steganography
  • MITRE ATT&CK technique mapping — auto-tags findings with MITRE IDs
  • YARA rule generation — creates hunt rules from unique strings/bytecode
  • STIX/MISP IOC export — machine-readable threat intel bundles

Dynamic analysis (Docker sandbox):

  • Runs the actual Minecraft client with the mod loaded
  • Plants fake Discord tokens and Minecraft session files as honeypots
  • Captures all network traffic with tcpdump
  • Monitors file system access with inotifywait, strace, and lsof
  • Disables SSL cert validation so malware C2 connections succeed
  • Dumps Java heap to extract runtime-decrypted strings
  • Compares container state before/after to find dropped files
  • Auto-downloads and analyzes stage-2 payloads if found

String extraction:

  • Static XOR brute-force decryptor for common obfuscation schemes
  • Dynamic reflection extractor for caller-context obfuscation (StackWalker-based)
  • Bytecode scanner that finds decryptor methods by signature + call frequency

Scripts

ScriptPurpose
jarsec-decrypt.pyStatic XOR brute-force string decryptor
jarsec-discover.pyBytecode scanner — finds candidate decryptor methods
jarsec-extract.pyDynamic reflection extractor — loads classes to get decrypted strings
jarsec-ioc.pySTIX 2.1 + MISP JSON IOC export
jarsec-yara.pyAuto-generates YARA rules from analysis findings
jarsec-mitre.pyMaps findings to MITRE ATT&CK techniques

Docker Sandbox

The skill can use a pre-built image (ghcr.io/tinywifi/jarsec-sandbox:latest) for fast startup, or build locally if unavailable. The image includes:

  • Eclipse Temurin JDK 21
  • Vineflower + CFR decompilers
  • tcpdump, tshark, strace, lsof, inotify-tools
  • xvfb for headless rendering
  • portablemc for Minecraft launching
  • python3 + pip3

How it works

  1. Figures out what you gave it (URL, file path, or current directory)
  2. Checks that Docker is installed
  3. Creates an isolated temp workspace (no cross-contamination between runs)
  4. Decompiles JARs to Java source with Vineflower (CFR fallback)
  5. Runs static decryptor + dynamic extractor for obfuscated strings
  6. Spawns 4 static analysis agents in parallel
  7. If it's source code, builds the mod first
  8. Spins up a throwaway Docker container and runs the mod inside it
  9. Watches filesystem events, network traffic, heap dumps, and process changes
  10. If stage-2 droppers found, downloads and analyzes them recursively
  11. Generates STIX/MISP IOCs, YARA rules, and MITRE mapping
  12. Gives you a report with a single word verdict: CLEAN, SUSPICIOUS, or MALICIOUS

Safety

The mod never touches your host. Everything dynamic happens inside a Docker container that gets destroyed after analysis. Even if the mod is pure evil, your machine is safe.

License

MIT

About

Jarsec Malware Analysis Task Force - Claude Code skill for analyzing Minecraft mods

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Jarsec

A Claude Code skill that analyzes Minecraft mods for malware. It does both static analysis (reading the code) and dynamic analysis (actually running the mod in a sandbox) to check for infostealers, RATs, obfuscation, C2 infrastructure, and other nasty stuff.

Install

npx skills add https://github.com/tinywifi/jarsec

What you need

  • Docker (required - the mod never runs on your actual machine)
  • Java (required for decompilation - openjdk-21-jdk or any JDK 17+)
  • Optional extras: unzip, tcpdump, tshark, strace, python3-pip

Decompilers (Vineflower + CFR fallback) are downloaded automatically on first run. The Docker sandbox image can be pre-built or built locally.

Jarsec will check what you have installed and tell you exactly what's missing.

How to use it

Analyze the source code in your current folder

claude
/jarsec

Analyze a local JAR file

claude
/jarsec /path/to/mod.jar

Download and analyze a JAR from a URL

claude
/jarsec https://cdn.modrinth.com/data/.../mod.jar

What it actually checks

Static analysis (4 agents running in parallel):

  • Decompiles JAR bytecode to readable Java source via Vineflower (falls back to CFR)
  • Build configuration for malicious repos, shadow jars, or obfuscation
  • Infostealer signatures (Discord webhooks, token grabbers, session theft)
  • Known Weedhack/majanito malware IOCs
  • Malicious APIs (Runtime.exec, ProcessBuilder, clipboard hijacking, etc.)
  • Persistence mechanisms (startup injection, registry keys, scheduled tasks)
  • Stage-2 droppers (OS fingerprinting, temp file writes, URLClassLoader)
  • Viral propagation (JAR/zip file iteration, self-replication)
  • Network C2 (hardcoded URLs, Telegram bots, blockchain/Ethereum C2)
  • Mixin review (checking if mixins intercept sensitive packets without good reason)
  • Unsafe deserialization (BleedingPipe vectors)
  • Reflection abuse, anti-sandbox checks, JVM instrumentation, steganography
  • MITRE ATT&CK technique mapping — auto-tags findings with MITRE IDs
  • YARA rule generation — creates hunt rules from unique strings/bytecode
  • STIX/MISP IOC export — machine-readable threat intel bundles

Dynamic analysis (Docker sandbox):

  • Runs the actual Minecraft client with the mod loaded
  • Plants fake Discord tokens and Minecraft session files as honeypots
  • Captures all network traffic with tcpdump
  • Monitors file system access with inotifywait, strace, and lsof
  • Disables SSL cert validation so malware C2 connections succeed
  • Dumps Java heap to extract runtime-decrypted strings
  • Compares container state before/after to find dropped files
  • Auto-downloads and analyzes stage-2 payloads if found

String extraction:

  • Static XOR brute-force decryptor for common obfuscation schemes
  • Dynamic reflection extractor for caller-context obfuscation (StackWalker-based)
  • Bytecode scanner that finds decryptor methods by signature + call frequency

Scripts

ScriptPurpose
jarsec-decrypt.pyStatic XOR brute-force string decryptor
jarsec-discover.pyBytecode scanner — finds candidate decryptor methods
jarsec-extract.pyDynamic reflection extractor — loads classes to get decrypted strings
jarsec-ioc.pySTIX 2.1 + MISP JSON IOC export
jarsec-yara.pyAuto-generates YARA rules from analysis findings
jarsec-mitre.pyMaps findings to MITRE ATT&CK techniques

Docker Sandbox

The skill can use a pre-built image (ghcr.io/tinywifi/jarsec-sandbox:latest) for fast startup, or build locally if unavailable. The image includes:

  • Eclipse Temurin JDK 21
  • Vineflower + CFR decompilers
  • tcpdump, tshark, strace, lsof, inotify-tools
  • xvfb for headless rendering
  • portablemc for Minecraft launching
  • python3 + pip3

How it works

  1. Figures out what you gave it (URL, file path, or current directory)
  2. Checks that Docker is installed
  3. Creates an isolated temp workspace (no cross-contamination between runs)
  4. Decompiles JARs to Java source with Vineflower (CFR fallback)
  5. Runs static decryptor + dynamic extractor for obfuscated strings
  6. Spawns 4 static analysis agents in parallel
  7. If it's source code, builds the mod first
  8. Spins up a throwaway Docker container and runs the mod inside it
  9. Watches filesystem events, network traffic, heap dumps, and process changes
  10. If stage-2 droppers found, downloads and analyzes them recursively
  11. Generates STIX/MISP IOCs, YARA rules, and MITRE mapping
  12. Gives you a report with a single word verdict: CLEAN, SUSPICIOUS, or MALICIOUS

Safety

The mod never touches your host. Everything dynamic happens inside a Docker container that gets destroyed after analysis. Even if the mod is pure evil, your machine is safe.

License

MIT

About

Jarsec Malware Analysis Task Force - Claude Code skill for analyzing Minecraft mods

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Jarsec

A Claude Code skill that analyzes Minecraft mods for malware. It does both static analysis (reading the code) and dynamic analysis (actually running the mod in a sandbox) to check for infostealers, RATs, obfuscation, C2 infrastructure, and other nasty stuff.

Install

npx skills add https://github.com/tinywifi/jarsec

What you need

  • Docker (required - the mod never runs on your actual machine)
  • Java (required for decompilation - openjdk-21-jdk or any JDK 17+)
  • Optional extras: unzip, tcpdump, tshark, strace, python3-pip

Decompilers (Vineflower + CFR fallback) are downloaded automatically on first run. The Docker sandbox image can be pre-built or built locally.

Jarsec will check what you have installed and tell you exactly what's missing.

How to use it

Analyze the source code in your current folder

claude
/jarsec

Analyze a local JAR file

claude
/jarsec /path/to/mod.jar

Download and analyze a JAR from a URL

claude
/jarsec https://cdn.modrinth.com/data/.../mod.jar

What it actually checks

Static analysis (4 agents running in parallel):

  • Decompiles JAR bytecode to readable Java source via Vineflower (falls back to CFR)
  • Build configuration for malicious repos, shadow jars, or obfuscation
  • Infostealer signatures (Discord webhooks, token grabbers, session theft)
  • Known Weedhack/majanito malware IOCs
  • Malicious APIs (Runtime.exec, ProcessBuilder, clipboard hijacking, etc.)
  • Persistence mechanisms (startup injection, registry keys, scheduled tasks)
  • Stage-2 droppers (OS fingerprinting, temp file writes, URLClassLoader)
  • Viral propagation (JAR/zip file iteration, self-replication)
  • Network C2 (hardcoded URLs, Telegram bots, blockchain/Ethereum C2)
  • Mixin review (checking if mixins intercept sensitive packets without good reason)
  • Unsafe deserialization (BleedingPipe vectors)
  • Reflection abuse, anti-sandbox checks, JVM instrumentation, steganography
  • MITRE ATT&CK technique mapping — auto-tags findings with MITRE IDs
  • YARA rule generation — creates hunt rules from unique strings/bytecode
  • STIX/MISP IOC export — machine-readable threat intel bundles

Dynamic analysis (Docker sandbox):

  • Runs the actual Minecraft client with the mod loaded
  • Plants fake Discord tokens and Minecraft session files as honeypots
  • Captures all network traffic with tcpdump
  • Monitors file system access with inotifywait, strace, and lsof
  • Disables SSL cert validation so malware C2 connections succeed
  • Dumps Java heap to extract runtime-decrypted strings
  • Compares container state before/after to find dropped files
  • Auto-downloads and analyzes stage-2 payloads if found

String extraction:

  • Static XOR brute-force decryptor for common obfuscation schemes
  • Dynamic reflection extractor for caller-context obfuscation (StackWalker-based)
  • Bytecode scanner that finds decryptor methods by signature + call frequency

Scripts

ScriptPurpose
jarsec-decrypt.pyStatic XOR brute-force string decryptor
jarsec-discover.pyBytecode scanner — finds candidate decryptor methods
jarsec-extract.pyDynamic reflection extractor — loads classes to get decrypted strings
jarsec-ioc.pySTIX 2.1 + MISP JSON IOC export
jarsec-yara.pyAuto-generates YARA rules from analysis findings
jarsec-mitre.pyMaps findings to MITRE ATT&CK techniques

Docker Sandbox

The skill can use a pre-built image (ghcr.io/tinywifi/jarsec-sandbox:latest) for fast startup, or build locally if unavailable. The image includes:

  • Eclipse Temurin JDK 21
  • Vineflower + CFR decompilers
  • tcpdump, tshark, strace, lsof, inotify-tools
  • xvfb for headless rendering
  • portablemc for Minecraft launching
  • python3 + pip3

How it works

  1. Figures out what you gave it (URL, file path, or current directory)
  2. Checks that Docker is installed
  3. Creates an isolated temp workspace (no cross-contamination between runs)
  4. Decompiles JARs to Java source with Vineflower (CFR fallback)
  5. Runs static decryptor + dynamic extractor for obfuscated strings
  6. Spawns 4 static analysis agents in parallel
  7. If it's source code, builds the mod first
  8. Spins up a throwaway Docker container and runs the mod inside it
  9. Watches filesystem events, network traffic, heap dumps, and process changes
  10. If stage-2 droppers found, downloads and analyzes them recursively
  11. Generates STIX/MISP IOCs, YARA rules, and MITRE mapping
  12. Gives you a report with a single word verdict: CLEAN, SUSPICIOUS, or MALICIOUS

Safety

The mod never touches your host. Everything dynamic happens inside a Docker container that gets destroyed after analysis. Even if the mod is pure evil, your machine is safe.

License

MIT

About

Jarsec Malware Analysis Task Force - Claude Code skill for analyzing Minecraft mods

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Jarsec

A Claude Code skill that analyzes Minecraft mods for malware. It does both static analysis (reading the code) and dynamic analysis (actually running the mod in a sandbox) to check for infostealers, RATs, obfuscation, C2 infrastructure, and other nasty stuff.

Install

npx skills add https://github.com/tinywifi/jarsec

What you need

  • Docker (required - the mod never runs on your actual machine)
  • Java (required for decompilation - openjdk-21-jdk or any JDK 17+)
  • Optional extras: unzip, tcpdump, tshark, strace, python3-pip

Decompilers (Vineflower + CFR fallback) are downloaded automatically on first run. The Docker sandbox image can be pre-built or built locally.

Jarsec will check what you have installed and tell you exactly what's missing.

How to use it

Analyze the source code in your current folder

claude
/jarsec

Analyze a local JAR file

claude
/jarsec /path/to/mod.jar

Download and analyze a JAR from a URL

claude
/jarsec https://cdn.modrinth.com/data/.../mod.jar

What it actually checks

Static analysis (4 agents running in parallel):

  • Decompiles JAR bytecode to readable Java source via Vineflower (falls back to CFR)
  • Build configuration for malicious repos, shadow jars, or obfuscation
  • Infostealer signatures (Discord webhooks, token grabbers, session theft)
  • Known Weedhack/majanito malware IOCs
  • Malicious APIs (Runtime.exec, ProcessBuilder, clipboard hijacking, etc.)
  • Persistence mechanisms (startup injection, registry keys, scheduled tasks)
  • Stage-2 droppers (OS fingerprinting, temp file writes, URLClassLoader)
  • Viral propagation (JAR/zip file iteration, self-replication)
  • Network C2 (hardcoded URLs, Telegram bots, blockchain/Ethereum C2)
  • Mixin review (checking if mixins intercept sensitive packets without good reason)
  • Unsafe deserialization (BleedingPipe vectors)
  • Reflection abuse, anti-sandbox checks, JVM instrumentation, steganography
  • MITRE ATT&CK technique mapping — auto-tags findings with MITRE IDs
  • YARA rule generation — creates hunt rules from unique strings/bytecode
  • STIX/MISP IOC export — machine-readable threat intel bundles

Dynamic analysis (Docker sandbox):

  • Runs the actual Minecraft client with the mod loaded
  • Plants fake Discord tokens and Minecraft session files as honeypots
  • Captures all network traffic with tcpdump
  • Monitors file system access with inotifywait, strace, and lsof
  • Disables SSL cert validation so malware C2 connections succeed
  • Dumps Java heap to extract runtime-decrypted strings
  • Compares container state before/after to find dropped files
  • Auto-downloads and analyzes stage-2 payloads if found

String extraction:

  • Static XOR brute-force decryptor for common obfuscation schemes
  • Dynamic reflection extractor for caller-context obfuscation (StackWalker-based)
  • Bytecode scanner that finds decryptor methods by signature + call frequency

Scripts

ScriptPurpose
jarsec-decrypt.pyStatic XOR brute-force string decryptor
jarsec-discover.pyBytecode scanner — finds candidate decryptor methods
jarsec-extract.pyDynamic reflection extractor — loads classes to get decrypted strings
jarsec-ioc.pySTIX 2.1 + MISP JSON IOC export
jarsec-yara.pyAuto-generates YARA rules from analysis findings
jarsec-mitre.pyMaps findings to MITRE ATT&CK techniques

Docker Sandbox

The skill can use a pre-built image (ghcr.io/tinywifi/jarsec-sandbox:latest) for fast startup, or build locally if unavailable. The image includes:

  • Eclipse Temurin JDK 21
  • Vineflower + CFR decompilers
  • tcpdump, tshark, strace, lsof, inotify-tools
  • xvfb for headless rendering
  • portablemc for Minecraft launching
  • python3 + pip3

How it works

  1. Figures out what you gave it (URL, file path, or current directory)
  2. Checks that Docker is installed
  3. Creates an isolated temp workspace (no cross-contamination between runs)
  4. Decompiles JARs to Java source with Vineflower (CFR fallback)
  5. Runs static decryptor + dynamic extractor for obfuscated strings
  6. Spawns 4 static analysis agents in parallel
  7. If it's source code, builds the mod first
  8. Spins up a throwaway Docker container and runs the mod inside it
  9. Watches filesystem events, network traffic, heap dumps, and process changes
  10. If stage-2 droppers found, downloads and analyzes them recursively
  11. Generates STIX/MISP IOCs, YARA rules, and MITRE mapping
  12. Gives you a report with a single word verdict: CLEAN, SUSPICIOUS, or MALICIOUS

Safety

The mod never touches your host. Everything dynamic happens inside a Docker container that gets destroyed after analysis. Even if the mod is pure evil, your machine is safe.

License

MIT

About

Jarsec Malware Analysis Task Force - Claude Code skill for analyzing Minecraft mods

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Jarsec

A Claude Code skill that analyzes Minecraft mods for malware. It does both static analysis (reading the code) and dynamic analysis (actually running the mod in a sandbox) to check for infostealers, RATs, obfuscation, C2 infrastructure, and other nasty stuff.

Install

npx skills add https://github.com/tinywifi/jarsec

What you need

  • Docker (required - the mod never runs on your actual machine)
  • Java (required for decompilation - openjdk-21-jdk or any JDK 17+)
  • Optional extras: unzip, tcpdump, tshark, strace, python3-pip

Decompilers (Vineflower + CFR fallback) are downloaded automatically on first run. The Docker sandbox image can be pre-built or built locally.

Jarsec will check what you have installed and tell you exactly what's missing.

How to use it

Analyze the source code in your current folder

claude
/jarsec

Analyze a local JAR file

claude
/jarsec /path/to/mod.jar

Download and analyze a JAR from a URL

claude
/jarsec https://cdn.modrinth.com/data/.../mod.jar

What it actually checks

Static analysis (4 agents running in parallel):

  • Decompiles JAR bytecode to readable Java source via Vineflower (falls back to CFR)
  • Build configuration for malicious repos, shadow jars, or obfuscation
  • Infostealer signatures (Discord webhooks, token grabbers, session theft)
  • Known Weedhack/majanito malware IOCs
  • Malicious APIs (Runtime.exec, ProcessBuilder, clipboard hijacking, etc.)
  • Persistence mechanisms (startup injection, registry keys, scheduled tasks)
  • Stage-2 droppers (OS fingerprinting, temp file writes, URLClassLoader)
  • Viral propagation (JAR/zip file iteration, self-replication)
  • Network C2 (hardcoded URLs, Telegram bots, blockchain/Ethereum C2)
  • Mixin review (checking if mixins intercept sensitive packets without good reason)
  • Unsafe deserialization (BleedingPipe vectors)
  • Reflection abuse, anti-sandbox checks, JVM instrumentation, steganography
  • MITRE ATT&CK technique mapping — auto-tags findings with MITRE IDs
  • YARA rule generation — creates hunt rules from unique strings/bytecode
  • STIX/MISP IOC export — machine-readable threat intel bundles

Dynamic analysis (Docker sandbox):

  • Runs the actual Minecraft client with the mod loaded
  • Plants fake Discord tokens and Minecraft session files as honeypots
  • Captures all network traffic with tcpdump
  • Monitors file system access with inotifywait, strace, and lsof
  • Disables SSL cert validation so malware C2 connections succeed
  • Dumps Java heap to extract runtime-decrypted strings
  • Compares container state before/after to find dropped files
  • Auto-downloads and analyzes stage-2 payloads if found

String extraction:

  • Static XOR brute-force decryptor for common obfuscation schemes
  • Dynamic reflection extractor for caller-context obfuscation (StackWalker-based)
  • Bytecode scanner that finds decryptor methods by signature + call frequency

Scripts

ScriptPurpose
jarsec-decrypt.pyStatic XOR brute-force string decryptor
jarsec-discover.pyBytecode scanner — finds candidate decryptor methods
jarsec-extract.pyDynamic reflection extractor — loads classes to get decrypted strings
jarsec-ioc.pySTIX 2.1 + MISP JSON IOC export
jarsec-yara.pyAuto-generates YARA rules from analysis findings
jarsec-mitre.pyMaps findings to MITRE ATT&CK techniques

Docker Sandbox

The skill can use a pre-built image (ghcr.io/tinywifi/jarsec-sandbox:latest) for fast startup, or build locally if unavailable. The image includes:

  • Eclipse Temurin JDK 21
  • Vineflower + CFR decompilers
  • tcpdump, tshark, strace, lsof, inotify-tools
  • xvfb for headless rendering
  • portablemc for Minecraft launching
  • python3 + pip3

How it works

  1. Figures out what you gave it (URL, file path, or current directory)
  2. Checks that Docker is installed
  3. Creates an isolated temp workspace (no cross-contamination between runs)
  4. Decompiles JARs to Java source with Vineflower (CFR fallback)
  5. Runs static decryptor + dynamic extractor for obfuscated strings
  6. Spawns 4 static analysis agents in parallel
  7. If it's source code, builds the mod first
  8. Spins up a throwaway Docker container and runs the mod inside it
  9. Watches filesystem events, network traffic, heap dumps, and process changes
  10. If stage-2 droppers found, downloads and analyzes them recursively
  11. Generates STIX/MISP IOCs, YARA rules, and MITRE mapping
  12. Gives you a report with a single word verdict: CLEAN, SUSPICIOUS, or MALICIOUS

Safety

The mod never touches your host. Everything dynamic happens inside a Docker container that gets destroyed after analysis. Even if the mod is pure evil, your machine is safe.

License

MIT

About

Jarsec Malware Analysis Task Force - Claude Code skill for analyzing Minecraft mods

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Jarsec

A Claude Code skill that analyzes Minecraft mods for malware. It does both static analysis (reading the code) and dynamic analysis (actually running the mod in a sandbox) to check for infostealers, RATs, obfuscation, C2 infrastructure, and other nasty stuff.

Install

npx skills add https://github.com/tinywifi/jarsec

What you need

  • Docker (required - the mod never runs on your actual machine)
  • Java (required for decompilation - openjdk-21-jdk or any JDK 17+)
  • Optional extras: unzip, tcpdump, tshark, strace, python3-pip

Decompilers (Vineflower + CFR fallback) are downloaded automatically on first run. The Docker sandbox image can be pre-built or built locally.

Jarsec will check what you have installed and tell you exactly what's missing.

How to use it

Analyze the source code in your current folder

claude
/jarsec

Analyze a local JAR file

claude
/jarsec /path/to/mod.jar

Download and analyze a JAR from a URL

claude
/jarsec https://cdn.modrinth.com/data/.../mod.jar

What it actually checks

Static analysis (4 agents running in parallel):

  • Decompiles JAR bytecode to readable Java source via Vineflower (falls back to CFR)
  • Build configuration for malicious repos, shadow jars, or obfuscation
  • Infostealer signatures (Discord webhooks, token grabbers, session theft)
  • Known Weedhack/majanito malware IOCs
  • Malicious APIs (Runtime.exec, ProcessBuilder, clipboard hijacking, etc.)
  • Persistence mechanisms (startup injection, registry keys, scheduled tasks)
  • Stage-2 droppers (OS fingerprinting, temp file writes, URLClassLoader)
  • Viral propagation (JAR/zip file iteration, self-replication)
  • Network C2 (hardcoded URLs, Telegram bots, blockchain/Ethereum C2)
  • Mixin review (checking if mixins intercept sensitive packets without good reason)
  • Unsafe deserialization (BleedingPipe vectors)
  • Reflection abuse, anti-sandbox checks, JVM instrumentation, steganography
  • MITRE ATT&CK technique mapping — auto-tags findings with MITRE IDs
  • YARA rule generation — creates hunt rules from unique strings/bytecode
  • STIX/MISP IOC export — machine-readable threat intel bundles

Dynamic analysis (Docker sandbox):

  • Runs the actual Minecraft client with the mod loaded
  • Plants fake Discord tokens and Minecraft session files as honeypots
  • Captures all network traffic with tcpdump
  • Monitors file system access with inotifywait, strace, and lsof
  • Disables SSL cert validation so malware C2 connections succeed
  • Dumps Java heap to extract runtime-decrypted strings
  • Compares container state before/after to find dropped files
  • Auto-downloads and analyzes stage-2 payloads if found

String extraction:

  • Static XOR brute-force decryptor for common obfuscation schemes
  • Dynamic reflection extractor for caller-context obfuscation (StackWalker-based)
  • Bytecode scanner that finds decryptor methods by signature + call frequency

Scripts

ScriptPurpose
jarsec-decrypt.pyStatic XOR brute-force string decryptor
jarsec-discover.pyBytecode scanner — finds candidate decryptor methods
jarsec-extract.pyDynamic reflection extractor — loads classes to get decrypted strings
jarsec-ioc.pySTIX 2.1 + MISP JSON IOC export
jarsec-yara.pyAuto-generates YARA rules from analysis findings
jarsec-mitre.pyMaps findings to MITRE ATT&CK techniques

Docker Sandbox

The skill can use a pre-built image (ghcr.io/tinywifi/jarsec-sandbox:latest) for fast startup, or build locally if unavailable. The image includes:

  • Eclipse Temurin JDK 21
  • Vineflower + CFR decompilers
  • tcpdump, tshark, strace, lsof, inotify-tools
  • xvfb for headless rendering
  • portablemc for Minecraft launching
  • python3 + pip3

How it works

  1. Figures out what you gave it (URL, file path, or current directory)
  2. Checks that Docker is installed
  3. Creates an isolated temp workspace (no cross-contamination between runs)
  4. Decompiles JARs to Java source with Vineflower (CFR fallback)
  5. Runs static decryptor + dynamic extractor for obfuscated strings
  6. Spawns 4 static analysis agents in parallel
  7. If it's source code, builds the mod first
  8. Spins up a throwaway Docker container and runs the mod inside it
  9. Watches filesystem events, network traffic, heap dumps, and process changes
  10. If stage-2 droppers found, downloads and analyzes them recursively
  11. Generates STIX/MISP IOCs, YARA rules, and MITRE mapping
  12. Gives you a report with a single word verdict: CLEAN, SUSPICIOUS, or MALICIOUS

Safety

The mod never touches your host. Everything dynamic happens inside a Docker container that gets destroyed after analysis. Even if the mod is pure evil, your machine is safe.

License

MIT

About

Jarsec Malware Analysis Task Force - Claude Code skill for analyzing Minecraft mods

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Jarsec

A Claude Code skill that analyzes Minecraft mods for malware. It does both static analysis (reading the code) and dynamic analysis (actually running the mod in a sandbox) to check for infostealers, RATs, obfuscation, C2 infrastructure, and other nasty stuff.

Install

npx skills add https://github.com/tinywifi/jarsec

What you need

  • Docker (required - the mod never runs on your actual machine)
  • Java (required for decompilation - openjdk-21-jdk or any JDK 17+)
  • Optional extras: unzip, tcpdump, tshark, strace, python3-pip

Decompilers (Vineflower + CFR fallback) are downloaded automatically on first run. The Docker sandbox image can be pre-built or built locally.

Jarsec will check what you have installed and tell you exactly what's missing.

How to use it

Analyze the source code in your current folder

claude
/jarsec

Analyze a local JAR file

claude
/jarsec /path/to/mod.jar

Download and analyze a JAR from a URL

claude
/jarsec https://cdn.modrinth.com/data/.../mod.jar

What it actually checks

Static analysis (4 agents running in parallel):

  • Decompiles JAR bytecode to readable Java source via Vineflower (falls back to CFR)
  • Build configuration for malicious repos, shadow jars, or obfuscation
  • Infostealer signatures (Discord webhooks, token grabbers, session theft)
  • Known Weedhack/majanito malware IOCs
  • Malicious APIs (Runtime.exec, ProcessBuilder, clipboard hijacking, etc.)
  • Persistence mechanisms (startup injection, registry keys, scheduled tasks)
  • Stage-2 droppers (OS fingerprinting, temp file writes, URLClassLoader)
  • Viral propagation (JAR/zip file iteration, self-replication)
  • Network C2 (hardcoded URLs, Telegram bots, blockchain/Ethereum C2)
  • Mixin review (checking if mixins intercept sensitive packets without good reason)
  • Unsafe deserialization (BleedingPipe vectors)
  • Reflection abuse, anti-sandbox checks, JVM instrumentation, steganography
  • MITRE ATT&CK technique mapping — auto-tags findings with MITRE IDs
  • YARA rule generation — creates hunt rules from unique strings/bytecode
  • STIX/MISP IOC export — machine-readable threat intel bundles

Dynamic analysis (Docker sandbox):

  • Runs the actual Minecraft client with the mod loaded
  • Plants fake Discord tokens and Minecraft session files as honeypots
  • Captures all network traffic with tcpdump
  • Monitors file system access with inotifywait, strace, and lsof
  • Disables SSL cert validation so malware C2 connections succeed
  • Dumps Java heap to extract runtime-decrypted strings
  • Compares container state before/after to find dropped files
  • Auto-downloads and analyzes stage-2 payloads if found

String extraction:

  • Static XOR brute-force decryptor for common obfuscation schemes
  • Dynamic reflection extractor for caller-context obfuscation (StackWalker-based)
  • Bytecode scanner that finds decryptor methods by signature + call frequency

Scripts

ScriptPurpose
jarsec-decrypt.pyStatic XOR brute-force string decryptor
jarsec-discover.pyBytecode scanner — finds candidate decryptor methods
jarsec-extract.pyDynamic reflection extractor — loads classes to get decrypted strings
jarsec-ioc.pySTIX 2.1 + MISP JSON IOC export
jarsec-yara.pyAuto-generates YARA rules from analysis findings
jarsec-mitre.pyMaps findings to MITRE ATT&CK techniques

Docker Sandbox

The skill can use a pre-built image (ghcr.io/tinywifi/jarsec-sandbox:latest) for fast startup, or build locally if unavailable. The image includes:

  • Eclipse Temurin JDK 21
  • Vineflower + CFR decompilers
  • tcpdump, tshark, strace, lsof, inotify-tools
  • xvfb for headless rendering
  • portablemc for Minecraft launching
  • python3 + pip3

How it works

  1. Figures out what you gave it (URL, file path, or current directory)
  2. Checks that Docker is installed
  3. Creates an isolated temp workspace (no cross-contamination between runs)
  4. Decompiles JARs to Java source with Vineflower (CFR fallback)
  5. Runs static decryptor + dynamic extractor for obfuscated strings
  6. Spawns 4 static analysis agents in parallel
  7. If it's source code, builds the mod first
  8. Spins up a throwaway Docker container and runs the mod inside it
  9. Watches filesystem events, network traffic, heap dumps, and process changes
  10. If stage-2 droppers found, downloads and analyzes them recursively
  11. Generates STIX/MISP IOCs, YARA rules, and MITRE mapping
  12. Gives you a report with a single word verdict: CLEAN, SUSPICIOUS, or MALICIOUS

Safety

The mod never touches your host. Everything dynamic happens inside a Docker container that gets destroyed after analysis. Even if the mod is pure evil, your machine is safe.

License

MIT

About

Jarsec Malware Analysis Task Force - Claude Code skill for analyzing Minecraft mods

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Jarsec

A Claude Code skill that analyzes Minecraft mods for malware. It does both static analysis (reading the code) and dynamic analysis (actually running the mod in a sandbox) to check for infostealers, RATs, obfuscation, C2 infrastructure, and other nasty stuff.

Install

npx skills add https://github.com/tinywifi/jarsec

What you need

  • Docker (required - the mod never runs on your actual machine)
  • Java (required for decompilation - openjdk-21-jdk or any JDK 17+)
  • Optional extras: unzip, tcpdump, tshark, strace, python3-pip

Decompilers (Vineflower + CFR fallback) are downloaded automatically on first run. The Docker sandbox image can be pre-built or built locally.

Jarsec will check what you have installed and tell you exactly what's missing.

How to use it

Analyze the source code in your current folder

claude
/jarsec

Analyze a local JAR file

claude
/jarsec /path/to/mod.jar

Download and analyze a JAR from a URL

claude
/jarsec https://cdn.modrinth.com/data/.../mod.jar

What it actually checks

Static analysis (4 agents running in parallel):

  • Decompiles JAR bytecode to readable Java source via Vineflower (falls back to CFR)
  • Build configuration for malicious repos, shadow jars, or obfuscation
  • Infostealer signatures (Discord webhooks, token grabbers, session theft)
  • Known Weedhack/majanito malware IOCs
  • Malicious APIs (Runtime.exec, ProcessBuilder, clipboard hijacking, etc.)
  • Persistence mechanisms (startup injection, registry keys, scheduled tasks)
  • Stage-2 droppers (OS fingerprinting, temp file writes, URLClassLoader)
  • Viral propagation (JAR/zip file iteration, self-replication)
  • Network C2 (hardcoded URLs, Telegram bots, blockchain/Ethereum C2)
  • Mixin review (checking if mixins intercept sensitive packets without good reason)
  • Unsafe deserialization (BleedingPipe vectors)
  • Reflection abuse, anti-sandbox checks, JVM instrumentation, steganography
  • MITRE ATT&CK technique mapping — auto-tags findings with MITRE IDs
  • YARA rule generation — creates hunt rules from unique strings/bytecode
  • STIX/MISP IOC export — machine-readable threat intel bundles

Dynamic analysis (Docker sandbox):

  • Runs the actual Minecraft client with the mod loaded
  • Plants fake Discord tokens and Minecraft session files as honeypots
  • Captures all network traffic with tcpdump
  • Monitors file system access with inotifywait, strace, and lsof
  • Disables SSL cert validation so malware C2 connections succeed
  • Dumps Java heap to extract runtime-decrypted strings
  • Compares container state before/after to find dropped files
  • Auto-downloads and analyzes stage-2 payloads if found

String extraction:

  • Static XOR brute-force decryptor for common obfuscation schemes
  • Dynamic reflection extractor for caller-context obfuscation (StackWalker-based)
  • Bytecode scanner that finds decryptor methods by signature + call frequency

Scripts

ScriptPurpose
jarsec-decrypt.pyStatic XOR brute-force string decryptor
jarsec-discover.pyBytecode scanner — finds candidate decryptor methods
jarsec-extract.pyDynamic reflection extractor — loads classes to get decrypted strings
jarsec-ioc.pySTIX 2.1 + MISP JSON IOC export
jarsec-yara.pyAuto-generates YARA rules from analysis findings
jarsec-mitre.pyMaps findings to MITRE ATT&CK techniques

Docker Sandbox

The skill can use a pre-built image (ghcr.io/tinywifi/jarsec-sandbox:latest) for fast startup, or build locally if unavailable. The image includes:

  • Eclipse Temurin JDK 21
  • Vineflower + CFR decompilers
  • tcpdump, tshark, strace, lsof, inotify-tools
  • xvfb for headless rendering
  • portablemc for Minecraft launching
  • python3 + pip3

How it works

  1. Figures out what you gave it (URL, file path, or current directory)
  2. Checks that Docker is installed
  3. Creates an isolated temp workspace (no cross-contamination between runs)
  4. Decompiles JARs to Java source with Vineflower (CFR fallback)
  5. Runs static decryptor + dynamic extractor for obfuscated strings
  6. Spawns 4 static analysis agents in parallel
  7. If it's source code, builds the mod first
  8. Spins up a throwaway Docker container and runs the mod inside it
  9. Watches filesystem events, network traffic, heap dumps, and process changes
  10. If stage-2 droppers found, downloads and analyzes them recursively
  11. Generates STIX/MISP IOCs, YARA rules, and MITRE mapping
  12. Gives you a report with a single word verdict: CLEAN, SUSPICIOUS, or MALICIOUS

Safety

The mod never touches your host. Everything dynamic happens inside a Docker container that gets destroyed after analysis. Even if the mod is pure evil, your machine is safe.

License

MIT

About

Jarsec Malware Analysis Task Force - Claude Code skill for analyzing Minecraft mods

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages