i need your help.

i need your help.

🎙 John Hammond 👥 2.2M 📅 August 18, 2025 ⏱ 21 min 👁 27K 📄 tutorial 🧭 2026-08-17
Available in: English (current) Français

Keywords

malwareMinecraftChatTriggersinfo stealerRAT

Summary

In this video, cybersecurity educator John Hammond analyzes a malicious Minecraft ChatTriggers module that was sent to him by a viewer. He begins by acknowledging his limited knowledge of the Minecraft modding community and asks viewers for help in understanding terms like Fabric, Hypixel, and ChatTriggers. He then downloads and examines the module in a Windows 11 virtual machine, using Sublime Text to inspect the code. The module, named ‘Bye-Bye Goldor’, contains obfuscated JavaScript that fetches additional payloads from hst.sh, a pastebin-like service. The first payload is a Discord webhook-based info stealer that exfiltrates Minecraft account data, including session tokens and UUIDs, from various launchers. The second payload establishes persistence by creating directories and a flag file, then downloads a third payload. The third payload is a full-featured RAT (Remote Access Trojan) with capabilities for command execution, screen streaming, webcam capture, keylogging, and credential theft from browsers and gaming platforms. Throughout the video, Hammond emphasizes the importance of analyzing malware in a safe environment and encourages community education. He also includes a sponsor segment for Cape, a privacy-focused mobile carrier.

180 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides substantial value by offering a real-world example of malware targeting the Minecraft community, which is often overlooked in mainstream cybersecurity education. The analysis is thorough, walking through each stage of the malware’s execution and clearly explaining the technical details. The argumentation is solid, as Hammond bases his conclusions on direct code inspection and logical reasoning. He also demonstrates good security practices by using a VM and cautioning viewers. However, the video’s reliance on community input for context (e.g., the meaning of certain Minecraft terms) shows a gap in his expertise, which he openly acknowledges. This does not detract from the core analysis but limits the video’s standalone educational value for those unfamiliar with the Minecraft modding scene.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates scientific rigor by methodically analyzing the malware’s code and providing clear explanations. The sources cited are primarily the malware samples and the hst.sh payloads, which are directly examined. The creator also references community resources like the ChatTriggers website and deobfuscation mappings, but these are not formally cited. The title ‘i need your help.’ is appropriate as it reflects the collaborative nature of the video, where the creator seeks community assistance. The content matches the title, as the video is both an analysis and a call for education. The sponsor segment is clearly separated and does not affect the scientific content.

238 words

Title / Content Match

The title 'i need your help.' accurately reflects the video's collaborative and educational intent, as the creator seeks community assistance in understanding the Minecraft modding community while analyzing malware.

Quality & Reliability

8/10

The video is a practical malware analysis tutorial, demonstrating a real-world threat in the Minecraft modding community. The analysis is clear and methodical, with the creator openly acknowledging his limited knowledge of the Minecraft modding ecosystem and inviting community input. The technical details are accurate and the approach is safe (using a VM). However, the video relies on community comments for context and does not provide formal citations, slightly reducing its standalone reliability.

Key Moments

Cited Sources

  • ChatTriggers — The official website for ChatTriggers, a modding framework for Minecraft, which the malware module is based on.
  • hst.sh — A pastebin-like service used by the malware to host and retrieve malicious payloads.
  • Minecraft Deobfuscator 3000 — A repository mentioned by the creator for deobfuscating Minecraft function names, though the exact URL is not provided.

Concurring Sources

  • ChatTriggers — The official website confirms the existence of ChatTriggers and its module system, which the malware abuses.
  • hst.sh — The service is accessible and matches the description of a pastebin-like site used for hosting payloads.

External References

Contribution & Novelties

This video provides a unique contribution by analyzing a real-world malware sample specifically targeting the Minecraft modding community, a niche area often not covered in mainstream cybersecurity content. It offers a hands-on tutorial on malware analysis, demonstrating how to safely inspect and understand malicious code. The video also highlights the importance of community collaboration in cybersecurity education.

Pour aller plus loin :

100 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level. This indicates a well-balanced video that is both informative and accessible, though it may require some prior knowledge to fully grasp the technical details.

Reliability 8/10

💬 The comments are overwhelmingly positive and constructive, with viewers appreciating the educational value and offering additional context about the Minecraft modding community. Many comments provide helpful explanations and resources, reflecting a collaborative and supportive atmosphere.