i don't think it's a backdoor as i have it installed on my own personal server. and nothing was picked up by wazuh. Wazuh would have warned ...
I've decrypted the code its 100% a backdoor!
First of all in the official Github that line of code is no where to be found.
After decrypting that obfuscated code it turns out it makes a HttpRequest towards
https://sayebrouhk.com/v2_/stage3.php?to=MYwr <-- Backdoor!
Please make sure to remove it. (Delete whole folder there is also a cipher in server.lua)
EDIT:
There is even more ciphers hidden in certain cars files such as vehicle_names
also there is one in the enginesounds folder.
I would suggest to clean it all up and look for it.
I don't feel like cleaning al this cars up from cipher.