cd ~/projects

~/projects $ cat pxsentinel/README.md

pxSentinel

Mar 2026·● live·10last push March 10, 2026

Server-side malware scanner for FiveM that finds known backdoors in loaded resources, alerts staff on Discord and can contain infected resources.

LuaFiveMDiscord Webhooks

Why it exists#

Backdoored resources are one of the most common ways FiveM servers get compromised: a leaked or "free" script ships with hidden code that phones home, hands out admin or wipes the server. pxSentinel scans every loaded resource for known backdoor and malware signatures so owners find out before the damage is done.

How it works#

  • Full startup scan of every resource once the server finishes starting, plus runtime detection for resources started later in the session.
  • Detailed reports in the console with remediation steps, and a formatted Discord alert to your staff webhook.
  • Optional containment: stop infected resources immediately, or halt the server entirely.
  • Safe matching: signatures are matched as plain text, so Lua pattern characters can never cause false matches or errors.
  • Allow list for trusted resources.

A trap worth knowing about#

Some backdoors hook onResourceStop and call os.exit() as a kill switch. Stopping the resource fires the hook, the process dies, and txAdmin restarts the server with the backdoor still in place. That's why auto-stop is off by default. The recommended response is to stop (not restart) the server from txAdmin, delete the infected resource from disk, then start the server again.

Built in Lua 5.4 and licensed under AGPL-3.0.

available for work
Alberta, CA--:-- --