Two Trusted Sources: Modrinth & CurseForge
Download mods from exactly two places: Modrinth (modern UI, fast review) and CurseForge (the veteran with the largest catalog). Both enforce developer verification and upload review. Searching 'download XX mod' in a search engine is the biggest risk — top results are often lookalike domains off by a letter or two, pixel-perfect clones whose download button serves a malicious jar.
The 5-Step File Check
After downloading, before dropping into mods/, spend 30 seconds:
| Step | Check | Red Flag |
|---|---|---|
| 1 Filename | Matches official release | Garbled text, double .jar.jar |
| 2 Size | Matches the official page | Suspiciously small (gutted and re-skinned) |
| 3 Contents | Classes + assets | .exe/.bat/.dll inside or absurdly obfuscated names |
| 4 Metadata | Sane fabric.mod.json / mods.toml | Empty or garbled author fields |
| 5 Multi-engine scan | Submit to VirusTotal | Any detection = discard (even false positives are a fair trade) |
Common Scam Scripts
Four patterns that dominated 2025-2026: 1) 'Install our downloader first' — any .exe downloader/accelerator is a 100% scam; mods are always a single jar; 2) 'Verify your account' — logging into a forum with Microsoft credentials is phishing; 3) 'Exclusive cracked version' — mods have nothing to crack; the word itself is bait; 4) 'Shader installer' files in Discord/QQ groups — group-file installers are a keylogger hotspot; use official zips only.
Extra Advice for Parents & Server Owners
For kids' PCs: enable Windows Controlled Folder Access to block writes outside .minecraft — it stops most downloader payloads. Server owners: pull server cores and plugins from official channels only, and test in a scratch instance before going live — several 2025 server breaches (player data + backup keys) started with a malicious jar an admin dropped into mods/. Safe downloading is lesson one; pair it with our conflict-troubleshooting guide to cover both big risks of modding.