Adds a short subsection under 后门 documenting the upstream author's
QQ-group claim that another contributor used a backdoor to remotely
read user files, with the chat screenshot as evidence.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Promote the standalone mapping/BACKDOOR.md into the main README so the
backdoor discussion (screen capture, RCE / file download / file browse
packets, the upstream author's contradictory responses) is visible
without an extra click. Includes captured Trace screenshots, the
ToString-leaked CPacketSystemInfo class and the author's QQ-chat /
Bilibili rebuttals.
File moves:
- mapping/BACKDOOR.md -> inlined into README
- mapping/screenshot-*.png -> img/ (alongside the other readme assets)
- Several new images under img/ (RCE, backdoor*, CPacketSystemInfo, meme)
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
The Forge mod entry point no longer works in this project, so the
build section was steering people toward a path that wouldn't load.
Reframe the two delivery shapes as Java Agent jar and hot-injector
EXE, with a callout that mods/ is unsupported.
Other readme drift caught in this pass:
- UPX listed as an optional common prerequisite with install
instructions (choco / upx.github.io) — the upxCompress task already
no-ops when upx isn't on PATH, this just makes the option visible.
- 使用注入器 步骤 updated for the Inject-button UI (previously
documented "double-click a row").
- 删除 stale "构建流程" 列表 in the injector section.
- 后门 段更新 + 布吉岛 段加删除线 reflecting current detection
status (user-authored edits picked up in the same commit).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Loader UI
- Replace the Win32 ListView loader window with a Qt6 Widgets
one. main.cpp + new MainWindow.h/cpp: QTableWidget showing
PID / Window Title / Window Class, QTimer auto-refresh every
1 s, double-click a row to inject. Title filter is built in
(startsWith "Minecraft" and not containing "Launcher"), so
HMCL / MultiMC / generic Java apps never show up.
- Dark Fusion theme + inline QSS so the single EXE looks the
same on any Windows version.
- native/vcpkg.json declares qtbase[widgets] and build.gradle's
new findVcpkg() detects VCPKG_ROOT / C:/vcpkg / D:/vcpkg /
~/vcpkg / D:/vcpkg-<version> and passes
-DCMAKE_TOOLCHAIN_FILE + -DVCPKG_TARGET_TRIPLET=
x64-windows-static so Qt is fully statically linked. Final
OpenZenLoader.exe stays single-file (~30 MB) with no Qt6*.dll
or vcruntime/msvcp DLL imports beyond Windows system DLLs.
- Drop the old ui.cpp and the now-unused run_ui() entry on
loader.h.
Patch transformer
- asm.patchify.loader.PatchTransformer.wrapInvoke now tries a
strict owner+name+desc match first, falling back to the
historical (owner || name) matcher only if strict turns up
nothing. The old loose matcher counted every Mth.*(FFF)F call
against a wrap aimed at Mth.lerp(FFF)F, so a same-method
sibling wrap that deleted its own site shifted later slice
indices and made onRenderPitchLerp miss.
LivingEntityRendererPatch
- With the strict matcher in place, onRenderPitchLerp's slice
drops from (4,4) to (1,1) - there is exactly one
Mth.lerp(FFF)F call site in LivingEntityRenderer.render
(pitch lerp), as verified via javap on the runtime srg jar.
onRenderHeadYawLerp keeps slice (2,2) (2nd of three
Mth.rotLerp calls = head yaw). No more "no call site of
m_14179_" warning at boot.
Scaffold
- Rename the BooleanSetting field from advancedBlockSearch to
sneak so the Java name matches the user-facing label ("Sneak").
README
- Add the vcpkg / Qt prerequisites and update the injector
usage section to describe the auto-refreshing UI + double-
click flow.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- Title no longer carries the [WIP] marker now that the DLL injection
and module restoration work has stabilised.
- Minor wording tweak in the early-build disclaimer.
- New "常见问题" section noting that Bujidao currently does not
detect the project (verified 2026-05-23) since its anti-cheat is
class-name blacklist based; suggest renaming classes at build time.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- README: announce QQ group 523522206 for project discussion.
- ZenClient: remove bootstrapForDll(). The DLL path went from
"GameLoaderBridge -> DllBootstrap.start -> new ZenClient" to just
"DllBootstrap.start -> registerPatches + installPatchesAndRetransform"
a few commits ago, so MinecraftPatch.onTick's existing lazy-init
now constructs the singleton on the next tick and no external
caller needs this helper anymore.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Ship a self-contained OpenZenLoader.exe (OpenZen.dll embedded as
RCDATA) that injects into a running Minecraft 1.20.1 Forge
javaw.exe and brings up the Zen client without -javaagent or a
mods/ entry. The existing Forge mod path stays intact.
Native (native/):
- DLL: JNI_GetCreatedJavaVMs + JVMTI late-attach via the JDK's
instrument.dll Agent_OnAttach to obtain a real Instrumentation;
URLClassLoader on the game loader loads a single bridge class.
- Loader EXE: Win32 listview of javaw.exe/java.exe processes
with window titles, CreateRemoteThread+LoadLibraryW injection,
embedded DLL extracted to %TEMP%\OpenZenLoader at runtime.
Java:
- shit.zen.dll.GameLoaderBridge re-defines every jar class onto
the Forge GameClassLoader (fixed-point retry for super-class
deps) and extracts non-class resources to
%TEMP%\openzen-resources-<pid>, exposed via the
openzen.resources system property.
- shit.zen.dll.DllBootstrap only runs Bootstrap.init +
registerPatches + installPatchesAndRetransform; ZenClient
construction stays on MinecraftPatch.onTick lazy-init.
- shit.zen.asm.Bootstrap parses mapping.srg, detects SRG vs
mojmap runtime via Minecraft.tick reflection, exposes
remapMethod/remapField used at 5 PatchTransformer match
points and from ReflectionUtil.
- ReflectionUtil.resolveField walks the superclass chain trying
SRG then mojmap on each level so e.g. activeEffects on
LocalPlayer resolves on LivingEntity.
- shit.zen.utils.misc.Assets unifies resource lookup with a
fallback to openzen.resources; fonts, cloud assets and WebUI
static files route through it.
- PatchAgent.installPatchesAndRetransform is now idempotent so
DllBootstrap and ZenClient.init can both call it safely.
Build:
- ./gradlew jar forge mod jar (unchanged)
- ./gradlew dll single-file Loader EXE in build/dist
- CMake auto-located via vswhere when VS 2022 ships it.
- README documents both paths and required toolchain.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Recreate the shit.zen.network.webui handlers (categories, modules,
toggle, get/set setting, static files) from Recaf and wire them into
the WebUI module so it serves a control panel from a configurable
local port. Ships a Tailwind-based panel under resources/webui/.
README: clarify that the deobfuscated jar is the latest one as of
2026-05-21 (rather than an old build, as some users seem to assume),
collapse a stray hard wrap, and link to a new paste/ subtree that
will track which modules were lifted from the Naven client.
Also rename KillAura.aimRange to attackRange to match the user-facing
'Attack Range' label and how the field is actually used in the in-FOV
check.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- Remove unused Encryption class (AES wrapper around shit.zen.utils)
and its construction from ZenClient bootstrap; drop dead TimerPatch
import.
- Defer ConfigManager.loadAll() and CommandManager.initCommands() so
configs load only after modules are registered, fixing values that
were silently discarded.
- Make isOwner() return true so the local user is treated as owner.
- Rename ZenClient.disconnectFromServer() to shutdown() and pin the
MinecraftPatch close hook to At.Type.HEAD so it runs before the
game tears down its subsystems.
- README: invite users to file issues / open PRs for missing features.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>