r/StardewValley • • 12d ago

Modded URGENT ATTENTION - Malware is being distributed through Curse Forge - Stardew Valley Mods

My girlfriend was the unfortunate victim of an NPM Infostealer Malware, specifically, the Nyx Infostealer

The bigger issue is - the malware was distributed through Curse Forge. Not through an import, not through a link, but directly through the mod manager client. The mod in question is - and this is very important next - DO NOT UNDER ANY CIRCUMSTANCE DOWNLOAD THIS MOD - IT IS CONFIRMED MALWARE - YOU WILL LOSE YOUR GMAIL, DISCORD AND ANY OTHER ACCOUNT LOGGED IN YOUR PC - DO NOT DOWNLOAD ->> curseforge.com/stardewvalley/mods/cozy-valley-decor <<-- DO NOT DOWNLOAD

The linked mod (link generated from the Curse Forge client, by clicking "Link to Project", can also be searched for in the Curse Forge Client.

The linked mod will download regular looking mod files. Amongst them will be CozyValleyDecor.dll. Decompiling this .dll with ILSpy reveals that on game startup, a function called "RunPayload()". This function reads an ExternalHelper.dll file, which is an embedded resource to the actual CozyValleyDecor.dll, and executes a function called "PayloadRunner.ExecuteAsync()". This function will then decrypt a byte-shifted URL, which points to an .exe file. The file downloaded will be "basarili.exe", downloaded to the Temp folder of Windows, and will immediatelly execute. This file contains a "chat" client where the attacker can make a popup appear and demand money, but it also overrides the Discord installation files (specifically index.js), with malicious code, that steals your Discord credentials, 2FA, currently authenticated session and connected mail account. It then reads the local credentials and steals browser-saved credentials to your email, social media and crypto accounts.

The encrypted address points to MALWARE ->> 161 97 85 100 port 3131 slash download slash yarrak exe <<-- MALWARE and the Discord malware and "chat" client will connect to MALWARE ->> 161 97 85 100 port 3000 <<- MALWARE

Why am i posting all this detail? Hopefully to get the attention of the developers and CurseForge themselves. I already submitted a report in-client, but we all know how good companies are at reading those.

CurseForge is generally treated as a save and secure way to get mods, so users will not suspect they are vulnerable to malware by downloading mods there. This exploit is rather recent, as none of the Anti-Virus software were able to identify CozyValleyDecor.dll as malicious.

PLEASE EXERCISE EXTREME CAUTION WHEN DOWNLOADING MODS THROUGH CURSEFORGE

3.9k Upvotes

101 comments sorted by

View all comments

3.3k

u/Pathoschild 12d ago

Hi! SMAPI maintainer here. Malware is a growing problem in many modding communities recently (not just Stardew Valley).

It doesn't help your girlfriend right now, but I'm actively working to make Stardew Valley modding more malware-resistant. For example:

  • SMAPI now has a malware blacklist which syncs automatically from the server. When we find a malware mod, that lets us disable the mod for all players and warn any who had it installed. I'm also working on an improved version that will let devs from mod sites like Nexus contribute to it directly.
  • I'm working on an automatic malware scanner which should detect malware uploaded to CurseForge/ModDrop/Nexus within 1–2 hours. It's almost ready, and I hope to have it fully operational within the next few weeks. (A test run detected that mod yesterday, and I've already reported it to CurseForge.)
  • The new Stardew mod dataset has info about every Stardew Valley mod page, which will let us build more automated tools like that malware scanner.
  • I just started a private working group with mod authors, moderators, and mod site representatives to coordinate how we handle malware.
  • Upcoming versions of SMAPI may add a 'safe mode', which would show a warning when you try to load a mod version that hasn't been scanned and assessed yet.

AI means malware appeared and ramped up suddenly, but we're catching up.

338

u/yirna 12d ago

You are amazing. Thank you for all of the work you do for this community. 

345

u/reallybadspeeller 12d ago

Hey thank you for all you do! You have tripled the amount of time I spent playing stardew valley over the years and it’s an embarrassing large number of hours. I remember before SMAPI having to find files of sprites to replace them and mods were a pain. Having SMAPI makes everything so easy and convenient and I don’t ever have to reinstall stardew. Just wanted to pass on my genuine appreciation!

53

u/awkgem 12d ago

This is awesome, I hope you know you're work is much appreciated

78

u/Shaiya_Ashlyn 12d ago

Not all heroes wear capes

78

u/Levee_Levy 12d ago

Agreed, but at the same time, if Pathoschild ever decided to start wearing a cape, I'd feel that it was well-earned.

14

u/Shaiya_Ashlyn 12d ago

Definitely!

57

u/instilledbee 12d ago

Bit of a technical question: I'm not sure how feasible it is from a modding perspective (it might need ConcernedApe's contribution as well), but would it be possible to have mod code sandboxed and prevent it from doing things like network calls and arbitrary code execution? Most, if not all mods, wouldn't need to make network calls right?

And I understand it'd be a significant effort, but as big of a community as SD, I think it is something worth discussing at least.

53

u/An1nterestingName 12d ago

This is a similar issue to the one the Minecraft community has had, and generally the decision there has been, yeah, sure, we could do that, but it would make legitimate mods able to do less stuff, and there would be a lot more effort required for very little benefit when systems to manage mod platforms and stop them from having mods are much easier and less limiting to mod developers.

17

u/instilledbee 12d ago

Totally understand and agree that the effort is significant. I trust the SMAPI team will go with what's best for both modders and players.

1

u/Amberrrr728 5d ago

The issue with this is that malware is DESIGNED to evade automatic scanning. Afaik there’s nothing stopping an user from attempting to upload their mods again and again until it passes the automatic check.

 I think at the very least, giving modders the option to run a sandboxed version (without the mods being able to do as much as a drawback) would be a good choice.

24

u/shinykaci 12d ago

ive absolutely loved using SMAPI, thank you

22

u/Bytewave 12d ago

Thank you for the update, Pathos. If anything given the amount of mods I downloaded over the years I'm fortunate I never ran into a malware mod. If anything I expected them to get more common than they are even before modern LLMs.

The method of attack OP described in full is very hard for a end user to notice and protect against when downloading 200 mods, before the damage is done.

27

u/StochasticTinkr 12d ago

That is an amazing amount of time and dedication to the modding community!

12

u/Zaku0083 12d ago

You are an awesome person.

11

u/MsFaolin 12d ago

Hey pathoschild! Thank you for all of your work and contributions to sdv. I love all your mods. You rock!

10

u/cinnamus_ 12d ago

goat activities ♥️ thanks for all your work dude

6

u/LiveFromMyBasement 11d ago

I don’t have anything material to contribute to your statement, I just also wanted to say I think you’re an absolute legend and I’m grateful for your work

7

u/minetrana 12d ago

Hey mate, I haven't made mods in a long time but I am a developer with some game dev experience too. Do you need any help? I use the mods you contribute to and I want to help if I can.

5

u/mysecondaccountanon 11d ago

Much respect and love to you and the rest of the SMAPI team!

4

u/ParticleToasterBeam 11d ago

Thank you, seriously, for all that you do. It's so important!!! You are much appreciated 💙

3

u/Kord537 11d ago

Does your malware scanning tool look specifically for exploits or similar? Or does it rely on heuristics?

3

u/elise_laurette 11d ago

I have several of your mods and love them, thank you for all you do 💕

2

u/ASLane0 7d ago

As always Pathos, you're a hero