Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
168 changes: 168 additions & 0 deletions 2026/10/2026-10-01-bephax.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,168 @@
While GitHub did not find sufficient information to determine a valid anti-circumvention claim, we determined that this takedown notice contains other valid copyright claim(s).

---

**Are you the copyright holder or authorized to act on the copyright owner's behalf? If you are submitting this notice on behalf of a company, please be sure to use an email address on the company's domain. If you use a personal email address for a notice submitted on behalf of a company, we may not be able to process it.**

Yes, I am the copyright holder.

**Are you submitting a revised DMCA notice after GitHub Trust & Safety requested you make changes to your original notice?**

Yes

**Please provide the Zendesk ticket number of your previously submitted notice. Zendesk ticket numbers are 7 digit ID numbers located in the subject line or body of your confirmation email.**

4701717

**Does your claim involve content on GitHub or npm.js?**

GitHub

**Please describe the nature of your copyright ownership or authorization to act on the owner's behalf.**

I am [private], the [private] [private] and copyright owner of BepHax, a proprietary, closed-source addon for the Meteor Client (Minecraft, Java/Fabric). [private] wrote the software and I own all rights in it. [private] never released its source code. [private] license compiled builds to paying customers exclusively through [private] [private] website, https://bep.dek.to, which [private] operate.

This is a revised notice, resubmitted in full as a single complete document at the request of [private] (Ticket 4701717), which asked me to include complete contact information.

My contact details:
[private]
[private]
Telephone: [private]
Email: [private]

**Please provide a detailed description of the original copyrighted work that has allegedly been infringed.**

THE COPYRIGHTED WORK

BepHax is a proprietary, closed-source Java program (an addon for the Meteor Client for Minecraft), currently at version 0.4.9. It is [private] original work. [private] never published its source code anywhere. Paying customers receive compiled .jar builds only, under license terms that permit neither redistribution nor reverse engineering. The only authorized distribution channel is [private] [private] [private] at https://bep.dek.to, which delivers builds only to authenticated, paid, hardware-bound customer accounts.

WHAT THE REPORTED REPOSITORY CONTAINS

The repository https://github.com/Cooperative-Karaboga/BepHax-NEW-SRC (default branch "main2") is a complete, unauthorized copy of that program, in two forms.

1) [private] COMPILED BINARIES, STILL PRESENT IN THE REPOSITORY'S HISTORY

On 26 August 2026 the uploaders committed [private] release .jar files for all six game versions [private] support: bephax_addon_v0.4.9-1.21.4.jar, bephax_addon_v0.4.9-1.21.5.jar, bephax_addon_v0.4.9-1.21.8.jar, bephax_addon_v0.4.9-1.21.11.jar, bephax_addon_v0.4.9-26.1.2.jar and bephax_addon_v0.4.9-26.2.jar (approximately 11.4 MB each). These are [private] [private] customer builds, obtained from [private] paid distribution channel and then modified to disable the license check (described in the anti-circumvention section of this notice). They are not available to the public from any authorized source.

They later deleted these files from the branch tip (commits c2335440, 90d66fc4, efbbaf63, 6b13530c, c5946ee9, 8a1a068f), but the files remain present and downloadable from the repository's git history. I verified this today by downloading one of them from:
https://github.com/Cooperative-Karaboga/BepHax-NEW-SRC/raw/aebc9aa7/bephax_addon_v0.4.9-1.21.11.jar
The full set is visible at:
https://github.com/Cooperative-Karaboga/BepHax-NEW-SRC/tree/aebc9aa7

For this reason, removing only the files currently visible on the branch would not remove [private] work. The repository as a whole, including its git history, must be taken down.

2) A DECOMPILATION OF THE SAME PROGRAM, PUBLISHED AS BUILDABLE SOURCE CODE

The tree src/main/java/bep/hax/ contains 316 Java files that are a machine decompilation of [private] compiled classes, repackaged as a Gradle project so that anyone can build a working copy of [private] paid product. It reproduces [private] package structure (bep.hax), [private] class names, [private] private field names, [private] constant values and [private] internal logic throughout.

HOW I VERIFIED THIS

I compared the repository against [private] private source tree. 44 files are byte-for-byte identical to [private] own original files, verified by matching Git blob SHA-1 hashes, including:

- src/main/java/bep/hax/util/EnemyColorManager.java
- src/main/java/bep/hax/util/HighwayBuilderConfigHolder.java
- 24 animation definition files under src/main/resources/assets/bephax/emotes/
- [private] emoji texture atlases src/main/resources/assets/bephax/textures/emoji/sheet_0.png through sheet_5.png
- [private] sound recordings src/main/resources/assets/bephax/sounds/patpat/pat.ogg, pat1.ogg and pat2.ogg
- [private] bundled configuration profiles src/main/resources/assets/bephax/profile/hud.nbt and modules.nbt
- [private] emoji index files src/main/resources/assets/bephax/emoji/codepoints.json and shortcodes.json

Furthermore, the copied file src/main/resources/fabric.mod.json still carries [private] own authorship metadata verbatim: mod id "bephax", authors "[private]" and "[private]", and [private] [private] repository URL [private]. It declares version 0.4.9, matching [private] current release.

The repository's README is titled "BepHax Free", displays the same six game versions [private] support, states "version 0.4.9", and expressly acknowledges that the project is derived from "the original BepHax client".

NO LICENSE OR AUTHORIZATION EXISTS

None of this is authorized. [private] work is not open source. I have granted no one a license to publish, redistribute, decompile or reverse engineer it. Neither the account that owns the repository nor the commit authors have any permission from [private]. The repository exists to give away for free the product [private] sell for a living, and it is doing direct and continuing financial damage to [private].

**If the original work referenced above is available online, please provide a URL.**

https://bep.dek.to

**We ask that a DMCA takedown notice list every specific file in the repository that is infringing, unless the entire contents of the repository are infringing on your copyright. Please clearly state that the entire repository is infringing, OR provide the specific files within the repository you would like removed.**

**Based on the above, I confirm that:**

The entire repository is infringing

**Identify the full repository URL that is infringing:**

https://github.com/Cooperative-Karaboga/BepHax-NEW-SRC

**Do you claim to have any technological measures in place to control access to your copyrighted content? Please see our <a href="https://docs.github.com/articles/guide-to-submitting-a-dmca-takedown-notice#complaints-about-anti-circumvention-technology">Complaints about Anti-Circumvention Technology</a> if you are unsure.**

Yes

**What technological measures do you have in place and how do they effectively control access to your copyrighted material?**

BepHax is distributed only as compiled Java bytecode, never as source, and every build contains an access-control layer that [private] wrote:

- bep.hax.license.LicenseValidator: on startup the addon authenticates to [private] server at bep.dek.to and refuses to run unless the server confirms a valid, paid, non-banned license.
- bep.hax.license.HWIDGenerator: derives a hardware identifier that is bound to the customer's account on first download, so a build cannot simply be copied to another machine and used.
- bep.hax.license.CredentialsCrypto and bep.hax.license.CredentialsLoader: encrypt and load the stored customer credentials used for that check.
- Delivery itself is gated. [private] server only serves a build after the customer's email, password and hardware ID have been validated against [private] license database, so the .jar files cannot be obtained at all without a paid account.

Together these measures control access both to the program and to the expression contained in it: without a valid paid license the software will not run, and without a paid account the compiled file cannot be obtained in the first place.

**How is the accused project designed to circumvent your technological protection measures?**

The project defeats [private] access control in two distinct ways, both of which I have verified directly.

1) THE COMPILED BUILDS IN THE REPOSITORY'S HISTORY HAVE [private] LICENSE CODE REPLACED WITH NO-OP STUBS.

I downloaded bephax_addon_v0.4.9-1.21.11.jar from the repository history at commit aebc9aa7 and disassembled it.[private] package bep/hax/license/ is still present, but five of its class files carry a modification timestamp of 2026-08-26 18:46 - the day of the upload, not [private] build date - and have been recompiled to do nothing:

- bep/hax/license/LicenseValidator.class: validate(String, String, String) no longer contacts [private] server at all. It unconditionally returns a new LicenseResponse("VALID", "License is valid").
- bep/hax/license/HWIDGenerator.class: generateHWID() has been reduced to a single instruction returning the string literal "PATCHED".
- bep/hax/license/LicenseManager.class: validateLicense() sets its validated flag to true and returns true; isValidated() returns true unconditionally; getFailureReason() returns null; showFailureMessage() and logStartupStatus() are empty; and the static initializer pre-sets validated to true.

[private] genuine classes perform an authenticated HTTPS request to bep.dek.to and refuse to run when it fails. The uploaded ones cannot fail, because they never ask. The word "PATCHED" is written into the binary by whoever modified it.

2) THE PUBLISHED SOURCE TREE HAS THE LICENSE PACKAGE DELETED ENTIRELY.

In the decompiled source they published, the bep.hax.license package is absent altogether. All seven of [private] files - LicenseValidator.java, LicenseManager.java, HWIDGenerator.java, CredentialsCrypto.java, CredentialsLoader.java, LicenseException.java and LicenseResponse.java - are gone, while every other package of mine is reproduced intact (bep.hax.modules, bep.hax.mixin, bep.hax.util, bep.hax.capes and the rest). Only the licensing code is missing.

The effect and the evident purpose is that [private] software runs without ever contacting [private] license server and without any hardware binding, so it never checks whether the user has paid. The repository is published under the title "BepHax Free" and is packaged as a ready-to-build Gradle project with the required mappings file included, so that any member of the public can build and run [private] paid product with the access control defeated. It is offered to the public for exactly that purpose.

**If you are reporting an allegedly infringing fork, please note that each fork is a distinct repository and <i>must be identified separately</i>. Please read more about <a href="https://docs.github.com/articles/dmca-takedown-policy#b-what-about-forks-or-whats-a-fork">forks.</a> As forks may often contain different material than in the parent repository, if you believe any of the repositories or files in the forks are infringing, please list each fork URL below:**

https://github.com/asdjrkxyz/BepHax-NEW-SRC

**Based on the representative number of forks I have reviewed, I believe that all or most of the forks are infringing to the same extent as the parent repository.**

**Is the work licensed under an open source license?**

No

**What would be the best solution for the alleged infringement?**

Reported content must be removed

**Do you have the alleged infringer’s contact information? If so, please provide it.**

I do not have their real-world contact information. I have only their GitHub identities:

- Repository owner: the organization account Cooperative-Karaboga (https://github.com/Cooperative-Karaboga)
- Commit author: [private], GitHub user ID [private] ([private])
- Commit author: [private], who uses the display name "[private]", GitHub user ID [private] ([private])
- Owner of the fork: asdjrkxyz ([private])

The uploaders published two screenshots in the repository itself which indicate how they obtained [private] software. image1.png is a screenshot of a [private] conversation in which the user "[private]" asks me to reset the hardware ID on a BepHax account and supplies the [private] transaction ID [private] as proof of purchase. image2.png is a screenshot of an AI chatbot producing that exact same string, [private], as an invented example of what a [private] transaction ID looks like. They appear to have posted these to boast about obtaining access to [private] paid distribution channel under false pretences.

I would also note, for the purposes of your repeat infringer policy, that this organization account appears to exist in order to redistribute other people's paid software. Its only other public repository, [private], is presented as a crack of a different commercial product.

**I have a good faith belief that use of the copyrighted materials described above on the infringing web pages is not authorized by the copyright owner, or its agent, or the law.**

**I have taken <a href="https://www.lumendatabase.org/topics/22">fair use</a> into consideration.**

**I swear, under penalty of perjury, that the information in this notification is accurate and that I am the copyright owner, or am authorized to act on behalf of the owner, of an exclusive right that is allegedly infringed.**

**I have read and understand GitHub's <a href="https://docs.github.com/articles/guide-to-submitting-a-dmca-takedown-notice/">Guide to Submitting a DMCA Takedown Notice</a>.**

**So that we can get back to you, please provide either your telephone number or physical address.**

[private], [private] Telephone: [private]. Email: [private]

**Please type your full name for your signature.**

[private]
Loading