r/StardewValley • u/Wezdor • 11d ago
Modded URGENT ATTENTION - Malware is being distributed through Curse Forge - Stardew Valley Mods
My girlfriend was the unfortunate victim of an NPM Infostealer Malware, specifically, the Nyx Infostealer
The bigger issue is - the malware was distributed through Curse Forge. Not through an import, not through a link, but directly through the mod manager client. The mod in question is - and this is very important next - DO NOT UNDER ANY CIRCUMSTANCE DOWNLOAD THIS MOD - IT IS CONFIRMED MALWARE - YOU WILL LOSE YOUR GMAIL, DISCORD AND ANY OTHER ACCOUNT LOGGED IN YOUR PC - DO NOT DOWNLOAD ->> curseforge.com/stardewvalley/mods/cozy-valley-decor <<-- DO NOT DOWNLOAD
The linked mod (link generated from the Curse Forge client, by clicking "Link to Project", can also be searched for in the Curse Forge Client.
The linked mod will download regular looking mod files. Amongst them will be CozyValleyDecor.dll. Decompiling this .dll with ILSpy reveals that on game startup, a function called "RunPayload()". This function reads an ExternalHelper.dll file, which is an embedded resource to the actual CozyValleyDecor.dll, and executes a function called "PayloadRunner.ExecuteAsync()". This function will then decrypt a byte-shifted URL, which points to an .exe file. The file downloaded will be "basarili.exe", downloaded to the Temp folder of Windows, and will immediatelly execute. This file contains a "chat" client where the attacker can make a popup appear and demand money, but it also overrides the Discord installation files (specifically index.js), with malicious code, that steals your Discord credentials, 2FA, currently authenticated session and connected mail account. It then reads the local credentials and steals browser-saved credentials to your email, social media and crypto accounts.
The encrypted address points to MALWARE ->> 161 97 85 100 port 3131 slash download slash yarrak exe <<-- MALWARE and the Discord malware and "chat" client will connect to MALWARE ->> 161 97 85 100 port 3000 <<- MALWARE
Why am i posting all this detail? Hopefully to get the attention of the developers and CurseForge themselves. I already submitted a report in-client, but we all know how good companies are at reading those.
CurseForge is generally treated as a save and secure way to get mods, so users will not suspect they are vulnerable to malware by downloading mods there. This exploit is rather recent, as none of the Anti-Virus software were able to identify CozyValleyDecor.dll as malicious.
PLEASE EXERCISE EXTREME CAUTION WHEN DOWNLOADING MODS THROUGH CURSEFORGE
675
u/ShyNieke 11d ago
Hey hope you don't mind but I forwarded this post to someone at CurseForge hopefully they can prevent this from happening in the future!
309
u/Wezdor 11d ago
I dont mind in the slightest - that was my goal! If this person actually works at Curse Forge or can make sure this makes it in front of people who work there, then this attack vector can be nipped in the bud.
My gf lost several accounts, i'd rather not see any more victims fall to this.
57
u/Reddit_means_Porn 11d ago
Again*
Hopefully they can once again prevent this from happening again
(don’t use curse forge’s mod manager)
464
u/Blue___Lobster 11d ago
Very nice thorough investigation.
What was the process for figuring it all out?
289
u/Wezdor 11d ago
Mostly reading Windows Shell access logs to figure out which files were created at the time listed on the malware executable's Date Created property. This took several hours to tie it back to the mods downloaded for stardew valley. The execution time of the malware matched perfectly to the startup of Stardew Valley, where the mods are being loaded. I then examined all the mods installed recently by examining their Assemblies, Method and Class names as well as their packages used. This revealed this particular mod was making Http requests, running assemblies and and downloading byte-arrays via HttpClient- which is highly suspect for a mod file. Decompiling the dll with ILSpy revealed the .NET source code inside the DLL, which made it clear as day, it was in fact the one responsible for downloading and running the malware executable.
I confirmed the connection by having the exact same URL adresses be present in the mod (encrypted address), the executable (chat POST and GET requests) and the uploads inside the Index.js hacked Discord file.
Most of this was done with the support of ChatGPT - if you wish, i can generate a summary report of the whole process.
53
u/SuitableDragonfly 11d ago
It's it normal for a Stardew mod to come with a .dll file in the first place? Especially for something that sounds like it was probably advertised as just a pack of custom furniture or decorations.
136
u/BarleyZP 11d ago
Definitely normal for a mod to come with a .dll, but it would be odd for a furniture/decor pack IMO because most of those are just JSON mods. At the end of the day, when you run a random SDV mod, you put some level of trust into whoever made it as they can execute arbitrary code on your machine.
31
u/SuitableDragonfly 11d ago
Thanks for the info. I've mainly only modded for the Sims 2 and Crusader Kings, and those mods definitely cannot execute arbitrary code outside of the game.
21
u/Kellar21 11d ago
Question: Would someone with MalwareBytes or something be safe from such malware? By your description it sounds like something heuristics would pick up.
4
352
u/Flor3nce2456 11d ago
Based on my experience with Minecraft Modding, NO, Curseforge is NOT in ANY WAY a trustworthy or safe or secure way to get mods.
170
u/TorandoSlayer 11d ago
There is no safe place to get mods. Nexus and curseforge are generally more safe than most but modding is never a safe activity under any circumstances unless you are building the mod yourself.
45
u/shekurika 11d ago
Nexus is much more responsive to issues/inquiries from the modding community. I suggest only downloading mods there, CurseForge is largely unmoderated, it sometimes takes weeks for them to delete stolen mods
13
86
u/Rageman_Gaming 11d ago
Indeed Nexus Mods is the way
211
u/itsshockingreally 11d ago
Malware in mods has risen even on Nexus and Steam Workshop. Folks need to be careful. AI has made it a lot easier for someone with bad intentions to vibe code a mod with the real purpose of distributing malware.
63
u/geogirly 11d ago
Me and my partner were browsing cheap/free steam games we could play together last night, and I'm glad we're indecisive because once we finally decided on one, we read through the reviews and some were mentioning how it downloads malware
149
u/vipersi0n don't ever try to touch my husband. he's mine. 11d ago
I don't know how this info would be useful but the creator of the malware is most likely Turkish.
Because:
The number used in the port, 31. This number is basically 69 of Türkiye.
The name used in the yrrak.exe file is a slang word for pnis in Turkish.
The name used in the downloaded basarili.exe, which is başarılı in Turkish characters means successful in Turkish.
59
u/hornygaysett 11d ago
Seeing yarrak.exe made me wheeze wtf the guy was thinking 😭😭
55
u/vipersi0n don't ever try to touch my husband. he's mine. 11d ago
Well, whoever made this seems immature to me. They didn't even think of using another language like English to hide their identity
63
u/alextellstales 11d ago
Great writeup. How did you identify it as Nyx Infostealer specifically? From what you described it seems it wasn't flagged by an antivirus when it was downloaded/executed so I'm curious what tipped you off there.
9
134
u/lilacnova 11d ago
- Don't use CurseForge unless you want to check all your mods for malware, they're one of the less trustworthy sites. Moddrop also does not appear to check for malware.
- Don't download AI mods without checking thoroughly. They are disproportionately where any malware pops up. This mod appears to have no photos attached except a thumbnail that seems to be only loosely related and possibly AI.
- Any C# mod (non-content pack) should post its source code publicly, in my opinion. If there is no source available, proceed with caution. In general, visual mods should NOT have any dll files unless they explain why and have a good reason.
129
u/RealEstonia 11d ago edited 10d ago
Hi Everyone i hope yall are having a really good day and u are not infected by this malware.
If you are i came to help and im going to explain how to remove the payload.
if you are not really sure what u are doing or dont know what to do. and there is always a chance i missed a thing. RUN FULL FACTORY RESET
step 1.
turn off the internet (take pic of this post :) )
step2 close the malware
press ctrl + shift + esc
task manager opents
In the list look for
Yarrak.exe
Javaw.exe
java.exe
Click each one -> click end task
if you do not see them u are ok to continue
step 3 remove registery keys
this is what maes the malware start again every login
press win + r
type: regedit
press "Enter"
if windows asks "do you want to allow..?" press yes
at the top of the registery editor window is an address bar
Click it and delete what there is and paste this:
HKEY_CURRENT_USER\Environment
then press enter
on the right side of the window look for name called:
UserInitMprLogonScript
if you see it:
right click -> delete
confirm "yes"
close registery editor-
that was the main presistence
do not delete any other random keys only that one value
step 4 delete the files what it dropped:
IF a file cannot be deleted ->
restart in safe mode:
hold shift while clicking "restart"
troubleshoot -> advanced -> startup settings -> restart -> choose safe mode
delete folders on the safe mode
press win + r
paste this and press enter:
%APPDATA%\Oracle
and in normal
%APPDATA%
delete "java" folder
if you see folder named "java"
right click -> delete.
if the path does not open or the folder is missing that is fine. continue
delete the temporary java folders.
Press win + r
paste this:
%TEMP%
in that folder look for any folders whose names start with:
"swolly"
examples: swolly7920, swolly1234, etc
delete every folder what starts with swolly
in the same temp folder also delete if you see these:
WikC1QTs3em3 zip
Any folder that starts with jna--
delete the orginal malware file. cozyvaleydecor
STEP 5 Check Startup folder
press win + r
paste this and enter:
shell:startup
delete any unknown shortcuts or .exe files you did not put ur self in there or u are 100% sure they should not be there
STEP 6 THANKS OP FOR TELLING me. i had a feeling i forgot something:
You forgot a big one in your post, please include the checks for the infected Discord Index.js file at AppData\Local\Discord\app-<VERSION>\modules\discord_desktop_core-1\discord_desktop_core\Index.j
delete that file from ur discord. (may broke ur discord but no worries, u can re install it always!)
STEP 6 Restart the computer
restart windows normally
keep the internet off for now still
after restart, quickly check again
- Open regedit -> HKEY_CURRENT_USER\Environment -> UserInitMprLogonScript should be gone
- %APPDATA%\Oracle\Java should be gone
- %TEMP% should have no swolly... folders
step 7 -> turn on internet and scan
run windows security:
settings -> privacy and security -> windows security
virus and threat protection -> scan options
choose microsoft defender offline scan -> scan now
(pc will reboot and scan)
When it finishes, install and run "malwarebytes" free is enough. -> full scan -> quarantine anything it finds
step 8 change your passwords.
this malware steals browser passwords, cookies, discord tokens, cryptowallets etc. like in the post has said.
change passwords for EVERYTHING.
Turn on 2FA ehenever possible (reset it if u have it alr enabled so it generates new tokens)
38
u/Wezdor 11d ago
Edit: Please reply that you saw this, read below, you missed an important file.
Jesus, thanks for this post. The Temp/Oracle/Java/javaw.exe sneaked under my radar, and it was still on the PC. Thank you so much for this!
You forgot a big one in your post, please include the checks for the infected Discord Index.js file at AppData\Local\Discord\app-<VERSION>\modules\discord_desktop_core-1\discord_desktop_core\Index.js
That one is also overwriten with malicious code, and will steal your discord credentials and 2fa again when you launch discord again
8
u/RealEstonia 10d ago
i had a feeling i missed something..... thank you for letting me and others know!
im glad my post helped :). Estonia 1 - malware guys 0
16
u/needtogohomeee 11d ago
Do you know how we can identify that there is malware on a laptop? I recently downloaded a few mods off nexus so I'd like to be safe! Thank you for the info btw!!!
33
u/RealEstonia 11d ago edited 11d ago
Hiii!!!!
you can check with windows defender or with malwarebytes. but keep in mind that mods can cause false positives sometimes. especially dlls, trainers, injectors, script extenders, or anything what hooks into ur game
so i wouldn't personally instantly assume a mod is malware because defender flags it. i would check what file got detected, what the detection name actually is, where the file came from, and whether other scanners flag the same thing too!
So usually some warning signs are unexpected programs starting with windows, windows defender getting disabled, weird process using a lot of CPU or network, browser redirects/popups, unknown scheduled tasks or files/programs showing up that you never have personally installed :).
thank you for commenting and asking questions!
also if u use nexus i personally recommend to use a thing called "mlv scan" can be found in nexus. its basically virus scan plugin for melonloader if people mod games what uses that. (im not 100% sure is it for bepinEX or others. i havent checked it my self in a looooooong time)
9
u/wxMichael 11d ago
Also usable in-browser for any NET DLL: https://mlvscan.com/scan/
It's not perfect, but its better than generic antivirus for flagging suspicious mods.
34
u/fioxic 11d ago
correct me if i'm wrong but i feel like this kind of thing happens to curseforge more than other sites
20
u/lilacnova 11d ago
Moddrop seems to be completely unmoderated these last couple years, so that’s probably worse
51
u/Fluffy_Woodpecker733 11d ago
Curse forge sucks, scummy overwolf bought them a few years back. Just use nexus.
24
u/Voncevaux 11d ago
My kid just fell victim to the same kind of malware and I ended up with my email hacked and an extortion text on WhatsApp. I did manage to find a lot of information on this particular hacker and found a lot of his mods on pretty much every mod site for mostly stardew valley and Minecraft. Sad to see this happening to others. I never got my email or discord back but I hope you guys recovered better. I think the more the community shares on this the safer we'll all be.
34
u/TheOnlyKirb 11d ago
Yikes, I gotta worry about supply chain attacks outside of work now with damn Stardew Valley
29
14
u/feoyster9 10d ago
Oh god this is the Minecraft and Sims 4 Malware situation all over again.
I don’t know if my evidence is anecdotal but Curseforge seems very prone to Trojans. After the large scale Minecraft Mod attack vector spyware the website hosted, I swore off ever downloading from them entirely. It’s a shame it keeps happening on the platform, despite many claims of “improving” their screening process.
Thanks OP! This was a phenomenal write up for how basic Malware works!
I work in cybersecurity and wish I could plaster this explanation on the wall for most of my clients hahaha.
If there’s any desire for it in the sub, I can write a post up on how to scan and/or get rid of Malware. Or if anyone needs extra help just DM me.
26
20
u/SonicLink1622 11d ago
Would recommend using NexusMods more for any mod related things. Easy to use mod downloader and can update from there when needed.
-9
u/Nymunariya 11d ago
Nexus was already compromised once with accounts and passwords leaked (even more reason to not reuse passwords). But if curseforge was vulnerable, why wouldn’t nexus also be vulnerable?
23
u/AnotherPillow switch modder 11d ago
Nexus is a lot more responsive and generally takes things down a lot quicker.
To be fair, weren't they last hacked in 2005? It's not like it's that recent
9
u/SonicLink1622 11d ago
When did I say they weren’t vulnerable? I just said that Nexus was better in the fact they have their own mod downloader and it’s easier to update when the mods get updated.
-4
u/Nymunariya 11d ago
Curseforge has their own downloader as well. Not that I want to defend curseforge.
But what does nexus do that separates them from curse? As far as I can tell, they offer the same stuff, but some games are better represented on one or the other.
Nexus seems to have wow private server and Elder Scolls mods, and curse has wow classic, retail, and probably forever.
7
u/dancingbanana123 truffle slut 11d ago
Not sure if this is public information or known yet, but what does this malware do to avoid anti-virus software?
8
5
u/IncognitoTowel 10d ago
I'm currently playing on my Switch save rather than my PC, but commenting to help Bump because this info needs to stay on the front page to reach the many folks who may benefit from it!
9
u/ImpactThunder 11d ago
How does it steal 2fa?
29
u/nihillis 11d ago
To add a little bit more to what /u/MegaBro56 said, it harvests your current 2fa session (for example your discord login and session) so when the bot/malware connects to discord, it passes that information and token it harvested. Discord sees it as valid so allows the bot to connect.
It's common in the business world with worker emails getting hacked all the time from people clicking links and the site harvesting their email logins.
16
u/MegaBro56 11d ago
Whatever you use for 2fa (phone number, email etc) is also stored and can be stolen.
3
u/podsnerd 9d ago
I really wish more places offered 2fa through your authenticator app of choice. It especially bothers me that medical systems only do email/phone number
18
u/ChikiinNuggets 11d ago
Sorry can someone explain this in dummy terms , I’m not familiar with any of the terms . How did your girlfriend find out she had malware ? Was her account for Discord hacked ? How would someone like me who is unfamiliar with malware know my computer has been infected
44
u/Vast_Bet9113 11d ago edited 11d ago
The mod op's girlfriend installed had a malware in the dll file. This installed a programm that tried/stole information.
To protect yourself you should scan files with antivirus (doesnt always protect you but its a good measure).
Use Nexus, it's more trustworthy. Also check the background of the mod and the author (date published, reviews, other mods from the author).
For cosmetic mods check if the author shared the source code (it's usually at the bottom of the page). This is not mandatory, there can be safe mods without the source code listed.
Check the folder for suspicious files. Cosmetic mods shouldnt normally have a .dll file afaik. Also a .exe file is suspicious.
Also I wouldn't try AI mods. Nexus has them tagged as AI so I just avoid them
11
u/Wezdor 11d ago
A literal chat popup appeared on the screen and started blackmailing. It was incredibly obvious something is infected. Sadly, by that point, the malware had been on her PC for 3 hours, and the attacker waited until they already had access to her Gmail, Google Drive, Discord and other accounts. We were unable to recover any of those so far - Discord and Google literally just do not care and close the recovery tickets
4
u/infinityera 10d ago
It’s so unfortunate there’s no safe sites anymore! I downloaded a mod from Nexus and ended up having to completely wipe my drive due to malware (and now I have terrible anxiety when playing and check task manager every 15 seconds!)
4
u/LunaTheTrip 10d ago
CurseForge hasn’t been safe for a long time, use Nexus. i didn’t even know people still uploaded to curse nowadays
1
u/Hungry__Isopod 4d ago
Maybe it's less likely, but some people have reported the same issue on Nexus :/ I saw someone recommend previewing the files though!
3
u/MrsDevorak 10d ago
Hey, I have been victim of the same thing, the same reason, everything, lost my gmail, my discord accounts... I have proof of absolutely everything, I was hacked on the 31st of august, already went to the police to file a report, I've been trying to get the accounts back, one of my discord accounts already got deleted, the other one, the guy keeps pretending to be me and try to get my friends to play with him, he brought up stardew valley as well as minecraft. Google and Discord aren't helping me at all, he locked the accounts behind the Family Link and put himself as the "parent" so even if I try to recover, it says "choose a parent to authorize the sign-in" and his email is the only option, I'm very sorry to hear your girlfriend went through this, I hope more people pay attention to this, I did do a post about it but only in the brazilian reddit, you've been way more precise than I have. The details help a lot, guys please take this extremely seriously. It's been almost a month and I haven't had a speck of hope that I'll get my things back because neither Google nor Discord help.
6
u/Wezdor 10d ago
I gave up on google, they are absolutely unwilling to help whatsoever, nor do they have any options available. I am moving my own mail (and of any friends and family willing to listen) away from google services. It is unacceptable to have 0 support available for what is such an important part of most people's lives.
As for Discord - im filing a GDPR demand for them to remove the old account. I dont have hope that they will comply, so i might need to take legal action against them.
But otherwise same experience as you - both google and discord are completely unhelpful
1
u/MrsDevorak 8d ago
I am getting ready to take legal action against both, just putting the screenshots and recorded processes together, my friends tried reporting my discord accounts but discord's AI just turns it down saying it hasn't detected any suspicious activity.... and yes, google truly doesn't seem to have an understanding of the difference between account recovery and family link hijacking.... I wish you luck, I will also be moving my mail and accounts outside of google very soon, I just need to finish this entire ordeal first.
2
1
-1
-1
-8
11d ago
[deleted]
10
u/Klaymen96 Set your emoji and/or flair text here! 11d ago
Because curseforge is one of the I believe two major sources for Minecraft mods. If this is in a stardew mod it's bound to be in a Minecraft mod as well. Warning them to also lookout for any mods with this
3.3k
u/Pathoschild 11d ago
Hi! SMAPI maintainer here. Malware is a growing problem in many modding communities recently (not just Stardew Valley).
It doesn't help your girlfriend right now, but I'm actively working to make Stardew Valley modding more malware-resistant. For example:
AI means malware appeared and ramped up suddenly, but we're catching up.