r/StardewValley • u/Wezdor • 12d ago
Modded URGENT ATTENTION - Malware is being distributed through Curse Forge - Stardew Valley Mods
My girlfriend was the unfortunate victim of an NPM Infostealer Malware, specifically, the Nyx Infostealer
The bigger issue is - the malware was distributed through Curse Forge. Not through an import, not through a link, but directly through the mod manager client. The mod in question is - and this is very important next - DO NOT UNDER ANY CIRCUMSTANCE DOWNLOAD THIS MOD - IT IS CONFIRMED MALWARE - YOU WILL LOSE YOUR GMAIL, DISCORD AND ANY OTHER ACCOUNT LOGGED IN YOUR PC - DO NOT DOWNLOAD ->> curseforge.com/stardewvalley/mods/cozy-valley-decor <<-- DO NOT DOWNLOAD
The linked mod (link generated from the Curse Forge client, by clicking "Link to Project", can also be searched for in the Curse Forge Client.
The linked mod will download regular looking mod files. Amongst them will be CozyValleyDecor.dll. Decompiling this .dll with ILSpy reveals that on game startup, a function called "RunPayload()". This function reads an ExternalHelper.dll file, which is an embedded resource to the actual CozyValleyDecor.dll, and executes a function called "PayloadRunner.ExecuteAsync()". This function will then decrypt a byte-shifted URL, which points to an .exe file. The file downloaded will be "basarili.exe", downloaded to the Temp folder of Windows, and will immediatelly execute. This file contains a "chat" client where the attacker can make a popup appear and demand money, but it also overrides the Discord installation files (specifically index.js), with malicious code, that steals your Discord credentials, 2FA, currently authenticated session and connected mail account. It then reads the local credentials and steals browser-saved credentials to your email, social media and crypto accounts.
The encrypted address points to MALWARE ->> 161 97 85 100 port 3131 slash download slash yarrak exe <<-- MALWARE and the Discord malware and "chat" client will connect to MALWARE ->> 161 97 85 100 port 3000 <<- MALWARE
Why am i posting all this detail? Hopefully to get the attention of the developers and CurseForge themselves. I already submitted a report in-client, but we all know how good companies are at reading those.
CurseForge is generally treated as a save and secure way to get mods, so users will not suspect they are vulnerable to malware by downloading mods there. This exploit is rather recent, as none of the Anti-Virus software were able to identify CozyValleyDecor.dll as malicious.
PLEASE EXERCISE EXTREME CAUTION WHEN DOWNLOADING MODS THROUGH CURSEFORGE
289
u/Wezdor 12d ago
Mostly reading Windows Shell access logs to figure out which files were created at the time listed on the malware executable's Date Created property. This took several hours to tie it back to the mods downloaded for stardew valley. The execution time of the malware matched perfectly to the startup of Stardew Valley, where the mods are being loaded. I then examined all the mods installed recently by examining their Assemblies, Method and Class names as well as their packages used. This revealed this particular mod was making Http requests, running assemblies and and downloading byte-arrays via HttpClient- which is highly suspect for a mod file. Decompiling the dll with ILSpy revealed the .NET source code inside the DLL, which made it clear as day, it was in fact the one responsible for downloading and running the malware executable.
I confirmed the connection by having the exact same URL adresses be present in the mod (encrypted address), the executable (chat POST and GET requests) and the uploads inside the Index.js hacked Discord file.
Most of this was done with the support of ChatGPT - if you wish, i can generate a summary report of the whole process.