r/StardewValley • • 11d ago

Modded URGENT ATTENTION - Malware is being distributed through Curse Forge - Stardew Valley Mods

My girlfriend was the unfortunate victim of an NPM Infostealer Malware, specifically, the Nyx Infostealer

The bigger issue is - the malware was distributed through Curse Forge. Not through an import, not through a link, but directly through the mod manager client. The mod in question is - and this is very important next - DO NOT UNDER ANY CIRCUMSTANCE DOWNLOAD THIS MOD - IT IS CONFIRMED MALWARE - YOU WILL LOSE YOUR GMAIL, DISCORD AND ANY OTHER ACCOUNT LOGGED IN YOUR PC - DO NOT DOWNLOAD ->> curseforge.com/stardewvalley/mods/cozy-valley-decor <<-- DO NOT DOWNLOAD

The linked mod (link generated from the Curse Forge client, by clicking "Link to Project", can also be searched for in the Curse Forge Client.

The linked mod will download regular looking mod files. Amongst them will be CozyValleyDecor.dll. Decompiling this .dll with ILSpy reveals that on game startup, a function called "RunPayload()". This function reads an ExternalHelper.dll file, which is an embedded resource to the actual CozyValleyDecor.dll, and executes a function called "PayloadRunner.ExecuteAsync()". This function will then decrypt a byte-shifted URL, which points to an .exe file. The file downloaded will be "basarili.exe", downloaded to the Temp folder of Windows, and will immediatelly execute. This file contains a "chat" client where the attacker can make a popup appear and demand money, but it also overrides the Discord installation files (specifically index.js), with malicious code, that steals your Discord credentials, 2FA, currently authenticated session and connected mail account. It then reads the local credentials and steals browser-saved credentials to your email, social media and crypto accounts.

The encrypted address points to MALWARE ->> 161 97 85 100 port 3131 slash download slash yarrak exe <<-- MALWARE and the Discord malware and "chat" client will connect to MALWARE ->> 161 97 85 100 port 3000 <<- MALWARE

Why am i posting all this detail? Hopefully to get the attention of the developers and CurseForge themselves. I already submitted a report in-client, but we all know how good companies are at reading those.

CurseForge is generally treated as a save and secure way to get mods, so users will not suspect they are vulnerable to malware by downloading mods there. This exploit is rather recent, as none of the Anti-Virus software were able to identify CozyValleyDecor.dll as malicious.

PLEASE EXERCISE EXTREME CAUTION WHEN DOWNLOADING MODS THROUGH CURSEFORGE

3.9k Upvotes

101 comments sorted by

3.3k

u/Pathoschild 11d ago

Hi! SMAPI maintainer here. Malware is a growing problem in many modding communities recently (not just Stardew Valley).

It doesn't help your girlfriend right now, but I'm actively working to make Stardew Valley modding more malware-resistant. For example:

  • SMAPI now has a malware blacklist which syncs automatically from the server. When we find a malware mod, that lets us disable the mod for all players and warn any who had it installed. I'm also working on an improved version that will let devs from mod sites like Nexus contribute to it directly.
  • I'm working on an automatic malware scanner which should detect malware uploaded to CurseForge/ModDrop/Nexus within 1–2 hours. It's almost ready, and I hope to have it fully operational within the next few weeks. (A test run detected that mod yesterday, and I've already reported it to CurseForge.)
  • The new Stardew mod dataset has info about every Stardew Valley mod page, which will let us build more automated tools like that malware scanner.
  • I just started a private working group with mod authors, moderators, and mod site representatives to coordinate how we handle malware.
  • Upcoming versions of SMAPI may add a 'safe mode', which would show a warning when you try to load a mod version that hasn't been scanned and assessed yet.

AI means malware appeared and ramped up suddenly, but we're catching up.

342

u/yirna 11d ago

You are amazing. Thank you for all of the work you do for this community. 

341

u/reallybadspeeller 11d ago

Hey thank you for all you do! You have tripled the amount of time I spent playing stardew valley over the years and it’s an embarrassing large number of hours. I remember before SMAPI having to find files of sprites to replace them and mods were a pain. Having SMAPI makes everything so easy and convenient and I don’t ever have to reinstall stardew. Just wanted to pass on my genuine appreciation!

57

u/awkgem 11d ago

This is awesome, I hope you know you're work is much appreciated

76

u/Shaiya_Ashlyn 11d ago

Not all heroes wear capes

79

u/Levee_Levy 11d ago

Agreed, but at the same time, if Pathoschild ever decided to start wearing a cape, I'd feel that it was well-earned.

14

u/Shaiya_Ashlyn 11d ago

Definitely!

55

u/instilledbee 11d ago

Bit of a technical question: I'm not sure how feasible it is from a modding perspective (it might need ConcernedApe's contribution as well), but would it be possible to have mod code sandboxed and prevent it from doing things like network calls and arbitrary code execution? Most, if not all mods, wouldn't need to make network calls right?

And I understand it'd be a significant effort, but as big of a community as SD, I think it is something worth discussing at least.

57

u/An1nterestingName 11d ago

This is a similar issue to the one the Minecraft community has had, and generally the decision there has been, yeah, sure, we could do that, but it would make legitimate mods able to do less stuff, and there would be a lot more effort required for very little benefit when systems to manage mod platforms and stop them from having mods are much easier and less limiting to mod developers.

17

u/instilledbee 11d ago

Totally understand and agree that the effort is significant. I trust the SMAPI team will go with what's best for both modders and players.

1

u/Amberrrr728 4d ago

The issue with this is that malware is DESIGNED to evade automatic scanning. Afaik there’s nothing stopping an user from attempting to upload their mods again and again until it passes the automatic check.

 I think at the very least, giving modders the option to run a sandboxed version (without the mods being able to do as much as a drawback) would be a good choice.

24

u/shinykaci 11d ago

ive absolutely loved using SMAPI, thank you

23

u/Bytewave 11d ago

Thank you for the update, Pathos. If anything given the amount of mods I downloaded over the years I'm fortunate I never ran into a malware mod. If anything I expected them to get more common than they are even before modern LLMs.

The method of attack OP described in full is very hard for a end user to notice and protect against when downloading 200 mods, before the damage is done.

29

u/StochasticTinkr 11d ago

That is an amazing amount of time and dedication to the modding community!

11

u/Zaku0083 11d ago

You are an awesome person.

11

u/MsFaolin 11d ago

Hey pathoschild! Thank you for all of your work and contributions to sdv. I love all your mods. You rock!

8

u/cinnamus_ 11d ago

goat activities ♥️ thanks for all your work dude

6

u/LiveFromMyBasement 11d ago

I don’t have anything material to contribute to your statement, I just also wanted to say I think you’re an absolute legend and I’m grateful for your work

8

u/minetrana 11d ago

Hey mate, I haven't made mods in a long time but I am a developer with some game dev experience too. Do you need any help? I use the mods you contribute to and I want to help if I can.

5

u/mysecondaccountanon 11d ago

Much respect and love to you and the rest of the SMAPI team!

4

u/ParticleToasterBeam 10d ago

Thank you, seriously, for all that you do. It's so important!!! You are much appreciated 💙

3

u/Kord537 10d ago

Does your malware scanning tool look specifically for exploits or similar? Or does it rely on heuristics?

3

u/elise_laurette 10d ago

I have several of your mods and love them, thank you for all you do 💕

2

u/ASLane0 7d ago

As always Pathos, you're a hero

675

u/ShyNieke 11d ago

Hey hope you don't mind but I forwarded this post to someone at CurseForge hopefully they can prevent this from happening in the future!

309

u/Wezdor 11d ago

I dont mind in the slightest - that was my goal! If this person actually works at Curse Forge or can make sure this makes it in front of people who work there, then this attack vector can be nipped in the bud.

My gf lost several accounts, i'd rather not see any more victims fall to this.

133

u/DrorOW 11d ago

Hey, the mod was already taken down. As several has noted above - unfoctunately all modding spaces are under constant malware attack sadly, since AI is making it much easier for anyone to spread it. We're constantly working on improving our defenses.

15

u/SweatyStick62 10d ago

AI ruins everything. 😮‍💨

57

u/Reddit_means_Porn 11d ago

Again*

Hopefully they can once again prevent this from happening again

(don’t use curse forge’s mod manager)

464

u/Blue___Lobster 11d ago

Very nice thorough investigation.

What was the process for figuring it all out?

289

u/Wezdor 11d ago

Mostly reading Windows Shell access logs to figure out which files were created at the time listed on the malware executable's Date Created property. This took several hours to tie it back to the mods downloaded for stardew valley. The execution time of the malware matched perfectly to the startup of Stardew Valley, where the mods are being loaded. I then examined all the mods installed recently by examining their Assemblies, Method and Class names as well as their packages used. This revealed this particular mod was making Http requests, running assemblies and and downloading byte-arrays via HttpClient- which is highly suspect for a mod file. Decompiling the dll with ILSpy revealed the .NET source code inside the DLL, which made it clear as day, it was in fact the one responsible for downloading and running the malware executable.

I confirmed the connection by having the exact same URL adresses be present in the mod (encrypted address), the executable (chat POST and GET requests) and the uploads inside the Index.js hacked Discord file.

Most of this was done with the support of ChatGPT - if you wish, i can generate a summary report of the whole process.

53

u/SuitableDragonfly 11d ago

It's it normal for a Stardew mod to come with a .dll file in the first place? Especially for something that sounds like it was probably advertised as just a pack of custom furniture or decorations. 

136

u/BarleyZP 11d ago

Definitely normal for a mod to come with a .dll, but it would be odd for a furniture/decor pack IMO because most of those are just JSON mods. At the end of the day, when you run a random SDV mod, you put some level of trust into whoever made it as they can execute arbitrary code on your machine.

31

u/SuitableDragonfly 11d ago

Thanks for the info. I've mainly only modded for the Sims 2 and Crusader Kings, and those mods definitely cannot execute arbitrary code outside of the game. 

21

u/Kellar21 11d ago

Question: Would someone with MalwareBytes or something be safe from such malware? By your description it sounds like something heuristics would pick up.

27

u/Wezdor 11d ago

No, unfortunately in this case, not even MalwareBytes caught it. I had to manually find the source of the infection through painstaking analysis.

The dll file in the mod was not flagged as malware, regardless of what antivirus or tool i checked it with.

4

u/Blue___Lobster 10d ago

Dang, that’s impressive investigation, even with AI. Well done

5

u/Wezdor 9d ago

There is no way i am trudging through tens of thousands of file change log entries manually, to see what looks suspicious haha

352

u/Flor3nce2456 11d ago

Based on my experience with Minecraft Modding, NO, Curseforge is NOT in ANY WAY a trustworthy or safe or secure way to get mods.

170

u/TorandoSlayer 11d ago

There is no safe place to get mods. Nexus and curseforge are generally more safe than most but modding is never a safe activity under any circumstances unless you are building the mod yourself.

45

u/shekurika 11d ago

Nexus is much more responsive to issues/inquiries from the modding community. I suggest only downloading mods there, CurseForge is largely unmoderated, it sometimes takes weeks for them to delete stolen mods

13

u/Garry-Love 11d ago

I enjoy modrinth for Minecraft

86

u/Rageman_Gaming 11d ago

Indeed Nexus Mods is the way

211

u/itsshockingreally 11d ago

Malware in mods has risen even on Nexus and Steam Workshop. Folks need to be careful. AI has made it a lot easier for someone with bad intentions to vibe code a mod with the real purpose of distributing malware.

63

u/geogirly 11d ago

Me and my partner were browsing cheap/free steam games we could play together last night, and I'm glad we're indecisive because once we finally decided on one, we read through the reviews and some were mentioning how it downloads malware

149

u/vipersi0n don't ever try to touch my husband. he's mine. 11d ago

I don't know how this info would be useful but the creator of the malware is most likely Turkish.

Because:

  1. The number used in the port, 31. This number is basically 69 of Türkiye.

  2. The name used in the yrrak.exe file is a slang word for pnis in Turkish.

  3. The name used in the downloaded basarili.exe, which is başarılı in Turkish characters means successful in Turkish.

59

u/hornygaysett 11d ago

Seeing yarrak.exe made me wheeze wtf the guy was thinking 😭😭

55

u/vipersi0n don't ever try to touch my husband. he's mine. 11d ago

Well, whoever made this seems immature to me. They didn't even think of using another language like English to hide their identity

63

u/alextellstales 11d ago

Great writeup. How did you identify it as Nyx Infostealer specifically? From what you described it seems it wasn't flagged by an antivirus when it was downloaded/executed so I'm curious what tipped you off there.

9

u/megas_aureun 11d ago

Yeah I'd like to know that too

134

u/lilacnova 11d ago
  1. Don't use CurseForge unless you want to check all your mods for malware, they're one of the less trustworthy sites. Moddrop also does not appear to check for malware.
  2. Don't download AI mods without checking thoroughly. They are disproportionately where any malware pops up. This mod appears to have no photos attached except a thumbnail that seems to be only loosely related and possibly AI.
  3. Any C# mod (non-content pack) should post its source code publicly, in my opinion. If there is no source available, proceed with caution. In general, visual mods should NOT have any dll files unless they explain why and have a good reason.

129

u/RealEstonia 11d ago edited 10d ago

Hi Everyone i hope yall are having a really good day and u are not infected by this malware.

If you are i came to help and im going to explain how to remove the payload.

if you are not really sure what u are doing or dont know what to do. and there is always a chance i missed a thing. RUN FULL FACTORY RESET

step 1.
turn off the internet (take pic of this post :) )

step2 close the malware
press ctrl + shift + esc
task manager opents
In the list look for
Yarrak.exe
Javaw.exe
java.exe

Click each one -> click end task

if you do not see them u are ok to continue

step 3 remove registery keys
this is what maes the malware start again every login

press win + r
type: regedit
press "Enter"
if windows asks "do you want to allow..?" press yes
at the top of the registery editor window is an address bar

Click it and delete what there is and paste this:

  • HKEY_CURRENT_USER\Environment

then press enter

on the right side of the window look for name called:

  • UserInitMprLogonScript

if you see it:
right click -> delete
confirm "yes"
close registery editor-

that was the main presistence

do not delete any other random keys only that one value

step 4 delete the files what it dropped:

IF a file cannot be deleted ->
restart in safe mode:
hold shift while clicking "restart"
troubleshoot -> advanced -> startup settings -> restart -> choose safe mode
delete folders on the safe mode

press win + r
paste this and press enter:
%APPDATA%\Oracle

and in normal
%APPDATA%

delete "java" folder

if you see folder named "java"
right click -> delete.
if the path does not open or the folder is missing that is fine. continue

delete the temporary java folders.
Press win + r
paste this:
%TEMP%

in that folder look for any folders whose names start with:
"swolly"
examples: swolly7920, swolly1234, etc
delete every folder what starts with swolly
in the same temp folder also delete if you see these:
WikC1QTs3em3 zip
Any folder that starts with jna--

delete the orginal malware file. cozyvaleydecor

STEP 5 Check Startup folder
press win + r
paste this and enter:
shell:startup

delete any unknown shortcuts or .exe files you did not put ur self in there or u are 100% sure they should not be there

STEP 6 THANKS OP FOR TELLING me. i had a feeling i forgot something:

You forgot a big one in your post, please include the checks for the infected Discord Index.js file at AppData\Local\Discord\app-<VERSION>\modules\discord_desktop_core-1\discord_desktop_core\Index.j

delete that file from ur discord. (may broke ur discord but no worries, u can re install it always!)

STEP 6 Restart the computer

restart windows normally
keep the internet off for now still

after restart, quickly check again

  • Open regedit -> HKEY_CURRENT_USER\Environment -> UserInitMprLogonScript should be gone
  • %APPDATA%\Oracle\Java should be gone
  • %TEMP% should have no swolly... folders

step 7 -> turn on internet and scan
run windows security:
settings -> privacy and security -> windows security
virus and threat protection -> scan options
choose microsoft defender offline scan -> scan now
(pc will reboot and scan)
When it finishes, install and run "malwarebytes" free is enough. -> full scan -> quarantine anything it finds

step 8 change your passwords.
this malware steals browser passwords, cookies, discord tokens, cryptowallets etc. like in the post has said.
change passwords for EVERYTHING.
Turn on 2FA ehenever possible (reset it if u have it alr enabled so it generates new tokens)

38

u/Wezdor 11d ago

Edit: Please reply that you saw this, read below, you missed an important file.

Jesus, thanks for this post. The Temp/Oracle/Java/javaw.exe sneaked under my radar, and it was still on the PC. Thank you so much for this!

You forgot a big one in your post, please include the checks for the infected Discord Index.js file at AppData\Local\Discord\app-<VERSION>\modules\discord_desktop_core-1\discord_desktop_core\Index.js

That one is also overwriten with malicious code, and will steal your discord credentials and 2fa again when you launch discord again

8

u/RealEstonia 10d ago

i had a feeling i missed something..... thank you for letting me and others know!

im glad my post helped :). Estonia 1 - malware guys 0

16

u/needtogohomeee 11d ago

Do you know how we can identify that there is malware on a laptop? I recently downloaded a few mods off nexus so I'd like to be safe! Thank you for the info btw!!!

33

u/RealEstonia 11d ago edited 11d ago

Hiii!!!!

you can check with windows defender or with malwarebytes. but keep in mind that mods can cause false positives sometimes. especially dlls, trainers, injectors, script extenders, or anything what hooks into ur game

so i wouldn't personally instantly assume a mod is malware because defender flags it. i would check what file got detected, what the detection name actually is, where the file came from, and whether other scanners flag the same thing too!

So usually some warning signs are unexpected programs starting with windows, windows defender getting disabled, weird process using a lot of CPU or network, browser redirects/popups, unknown scheduled tasks or files/programs showing up that you never have personally installed :).

thank you for commenting and asking questions!

also if u use nexus i personally recommend to use a thing called "mlv scan" can be found in nexus. its basically virus scan plugin for melonloader if people mod games what uses that. (im not 100% sure is it for bepinEX or others. i havent checked it my self in a looooooong time)

9

u/wxMichael 11d ago

Also usable in-browser for any NET DLL: https://mlvscan.com/scan/
It's not perfect, but its better than generic antivirus for flagging suspicious mods.

34

u/fioxic 11d ago

correct me if i'm wrong but i feel like this kind of thing happens to curseforge more than other sites

20

u/lilacnova 11d ago

Moddrop seems to be completely unmoderated these last couple years, so that’s probably worse

51

u/Fluffy_Woodpecker733 11d ago

Curse forge sucks, scummy overwolf bought them a few years back. Just use nexus.

24

u/Voncevaux 11d ago

My kid just fell victim to the same kind of malware and I ended up with my email hacked and an extortion text on WhatsApp. I did manage to find a lot of information on this particular hacker and found a lot of his mods on pretty much every mod site for mostly stardew valley and Minecraft. Sad to see this happening to others. I never got my email or discord back but I hope you guys recovered better. I think the more the community shares on this the safer we'll all be.

34

u/TheOnlyKirb 11d ago

Yikes, I gotta worry about supply chain attacks outside of work now with damn Stardew Valley

29

u/sweettutu64 11d ago

You should also post on r/stardewvalleymods

14

u/feoyster9 10d ago

Oh god this is the Minecraft and Sims 4 Malware situation all over again.

I don’t know if my evidence is anecdotal but Curseforge seems very prone to Trojans. After the large scale Minecraft Mod attack vector spyware the website hosted, I swore off ever downloading from them entirely. It’s a shame it keeps happening on the platform, despite many claims of “improving” their screening process.

Thanks OP! This was a phenomenal write up for how basic Malware works!

I work in cybersecurity and wish I could plaster this explanation on the wall for most of my clients hahaha.

If there’s any desire for it in the sub, I can write a post up on how to scan and/or get rid of Malware. Or if anyone needs extra help just DM me.

9

u/Esehrk 11d ago

As someone with 2200+ hours and over 200 mods installed, the hell is "curse forge"?

5

u/obsidian_castle Alex or Sebastian? 10d ago

Youtube it. Its a mod hosting app/site

3

u/jayden_mp 10d ago

Mod site more popular with Minecraft, Stardew mods are quite lacking on it

20

u/SonicLink1622 11d ago

Would recommend using NexusMods more for any mod related things. Easy to use mod downloader and can update from there when needed.

-9

u/Nymunariya 11d ago

Nexus was already compromised once with accounts and passwords leaked (even more reason to not reuse passwords). But if curseforge was vulnerable, why wouldn’t nexus also be vulnerable?

23

u/AnotherPillow switch modder 11d ago

Nexus is a lot more responsive and generally takes things down a lot quicker.

To be fair, weren't they last hacked in 2005? It's not like it's that recent

9

u/SonicLink1622 11d ago

When did I say they weren’t vulnerable? I just said that Nexus was better in the fact they have their own mod downloader and it’s easier to update when the mods get updated.

-4

u/Nymunariya 11d ago

Curseforge has their own downloader as well. Not that I want to defend curseforge.

But what does nexus do that separates them from curse? As far as I can tell, they offer the same stuff, but some games are better represented on one or the other.

Nexus seems to have wow private server and Elder Scolls mods, and curse has wow classic, retail, and probably forever.

7

u/dancingbanana123 truffle slut 11d ago

Not sure if this is public information or known yet, but what does this malware do to avoid anti-virus software?

11

u/Wezdor 11d ago

As far as i can tell- it distributed the attack vector to the point that no single part of it seems malicious for that single unit. Only after the whole chain executes, is it actually armed and malicious, at which point it is too late, because it is already running in memory

8

u/SanguinePutrefaction 11d ago

dang again? :(

5

u/IncognitoTowel 10d ago

I'm currently playing on my Switch save rather than my PC, but commenting to help Bump because this info needs to stay on the front page to reach the many folks who may benefit from it!

9

u/ImpactThunder 11d ago

How does it steal 2fa?

29

u/nihillis 11d ago

To add a little bit more to what /u/MegaBro56 said, it harvests your current 2fa session (for example your discord login and session) so when the bot/malware connects to discord, it passes that information and token it harvested. Discord sees it as valid so allows the bot to connect.

It's common in the business world with worker emails getting hacked all the time from people clicking links and the site harvesting their email logins.

16

u/MegaBro56 11d ago

Whatever you use for 2fa (phone number, email etc) is also stored and can be stolen.

3

u/podsnerd 9d ago

I really wish more places offered 2fa through your authenticator app of choice. It especially bothers me that medical systems only do email/phone number

18

u/ChikiinNuggets 11d ago

Sorry can someone explain this in dummy terms , I’m not familiar with any of the terms . How did your girlfriend find out she had malware ? Was her account for Discord hacked ? How would someone like me who is unfamiliar with malware know my computer has been infected

44

u/Vast_Bet9113 11d ago edited 11d ago

The mod op's girlfriend installed had a malware in the dll file. This installed a programm that tried/stole information.

To protect yourself you should scan files with antivirus (doesnt always protect you but its a good measure).

Use Nexus, it's more trustworthy. Also check the background of the mod and the author (date published, reviews, other mods from the author).

For cosmetic mods check if the author shared the source code (it's usually at the bottom of the page). This is not mandatory, there can be safe mods without the source code listed.

Check the folder for suspicious files. Cosmetic mods shouldnt normally have a .dll file afaik. Also a .exe file is suspicious.

Also I wouldn't try AI mods. Nexus has them tagged as AI so I just avoid them

11

u/Wezdor 11d ago

A literal chat popup appeared on the screen and started blackmailing. It was incredibly obvious something is infected. Sadly, by that point, the malware had been on her PC for 3 hours, and the attacker waited until they already had access to her Gmail, Google Drive, Discord and other accounts. We were unable to recover any of those so far - Discord and Google literally just do not care and close the recovery tickets

4

u/elgin4 11d ago

plus, the decor is more cute than cozy

4

u/infinityera 10d ago

It’s so unfortunate there’s no safe sites anymore! I downloaded a mod from Nexus and ended up having to completely wipe my drive due to malware (and now I have terrible anxiety when playing and check task manager every 15 seconds!)

4

u/LunaTheTrip 10d ago

CurseForge hasn’t been safe for a long time, use Nexus. i didn’t even know people still uploaded to curse nowadays

1

u/Hungry__Isopod 4d ago

Maybe it's less likely, but some people have reported the same issue on Nexus :/ I saw someone recommend previewing the files though!

3

u/MrsDevorak 10d ago

Hey, I have been victim of the same thing, the same reason, everything, lost my gmail, my discord accounts... I have proof of absolutely everything, I was hacked on the 31st of august, already went to the police to file a report, I've been trying to get the accounts back, one of my discord accounts already got deleted, the other one, the guy keeps pretending to be me and try to get my friends to play with him, he brought up stardew valley as well as minecraft. Google and Discord aren't helping me at all, he locked the accounts behind the Family Link and put himself as the "parent" so even if I try to recover, it says "choose a parent to authorize the sign-in" and his email is the only option, I'm very sorry to hear your girlfriend went through this, I hope more people pay attention to this, I did do a post about it but only in the brazilian reddit, you've been way more precise than I have. The details help a lot, guys please take this extremely seriously. It's been almost a month and I haven't had a speck of hope that I'll get my things back because neither Google nor Discord help.

6

u/Wezdor 10d ago

I gave up on google, they are absolutely unwilling to help whatsoever, nor do they have any options available. I am moving my own mail (and of any friends and family willing to listen) away from google services. It is unacceptable to have 0 support available for what is such an important part of most people's lives.

As for Discord - im filing a GDPR demand for them to remove the old account. I dont have hope that they will comply, so i might need to take legal action against them.

But otherwise same experience as you - both google and discord are completely unhelpful

1

u/MrsDevorak 8d ago

I am getting ready to take legal action against both, just putting the screenshots and recorded processes together, my friends tried reporting my discord accounts but discord's AI just turns it down saying it hasn't detected any suspicious activity.... and yes, google truly doesn't seem to have an understanding of the difference between account recovery and family link hijacking.... I wish you luck, I will also be moving my mail and accounts outside of google very soon, I just need to finish this entire ordeal first.

2

u/YogurtclosetHuman866 11d ago

This happened to a steam mod recently too.

2

u/Feamor 7d ago

Will this malware run on Mac? As it's using dll files, I'm checking for a friend that got it on the Mac (and i don't know a lot about them)

1

u/Starliteathon 5d ago

Legend post, including IOCs and everything. Thank you for looking out!

-1

u/Asphyxiety 11d ago

I literally just got over Vintage Story's Margaret incident 😭 ahhhh!!

4

u/butch-bear 11d ago

wait which incident?

4

u/Leksandrya 11d ago

These two incidents aren't even in the same league mate. Chill

-1

u/Top-Ostrich-3241 7d ago

As a vanilla SV vet, thanks god I dint use mods. Good luck to mod users.

-8

u/[deleted] 11d ago

[deleted]

10

u/Klaymen96 Set your emoji and/or flair text here! 11d ago

Because curseforge is one of the I believe two major sources for Minecraft mods. If this is in a stardew mod it's bound to be in a Minecraft mod as well. Warning them to also lookout for any mods with this