However, cybersecurity experts also warned that while the current code was clean, the infrastructure was compromised. Because the maintainer controlled the GitHub repository and the auto-update mechanism, they had the capability to push a malicious update at any moment.
Almost overnight, a tool used by children and gamers worldwide to play a voxel building game became a flashpoint in the culture wars.
The following is a feature-style piece covering the PolyMC situation, the controversy surrounding the "safe" label, and the broader implications for the open-source community.
The technical community quickly mobilized to answer the "safety" question.
The safety of is a complex topic rooted in a controversial 2022 internal dispute rather than a confirmed malware infection . While the software itself is currently considered technically functional, many in the Minecraft community advise against using it due to concerns over its centralized management. The Security Controversy (October 2022)
: The lead maintainer abruptly removed all other contributors and deleted the project's Code of Conduct.
The concern was multifaceted.