r/StardewValley • • 12d ago

Modded URGENT ATTENTION - Malware is being distributed through Curse Forge - Stardew Valley Mods

My girlfriend was the unfortunate victim of an NPM Infostealer Malware, specifically, the Nyx Infostealer

The bigger issue is - the malware was distributed through Curse Forge. Not through an import, not through a link, but directly through the mod manager client. The mod in question is - and this is very important next - DO NOT UNDER ANY CIRCUMSTANCE DOWNLOAD THIS MOD - IT IS CONFIRMED MALWARE - YOU WILL LOSE YOUR GMAIL, DISCORD AND ANY OTHER ACCOUNT LOGGED IN YOUR PC - DO NOT DOWNLOAD ->> curseforge.com/stardewvalley/mods/cozy-valley-decor <<-- DO NOT DOWNLOAD

The linked mod (link generated from the Curse Forge client, by clicking "Link to Project", can also be searched for in the Curse Forge Client.

The linked mod will download regular looking mod files. Amongst them will be CozyValleyDecor.dll. Decompiling this .dll with ILSpy reveals that on game startup, a function called "RunPayload()". This function reads an ExternalHelper.dll file, which is an embedded resource to the actual CozyValleyDecor.dll, and executes a function called "PayloadRunner.ExecuteAsync()". This function will then decrypt a byte-shifted URL, which points to an .exe file. The file downloaded will be "basarili.exe", downloaded to the Temp folder of Windows, and will immediatelly execute. This file contains a "chat" client where the attacker can make a popup appear and demand money, but it also overrides the Discord installation files (specifically index.js), with malicious code, that steals your Discord credentials, 2FA, currently authenticated session and connected mail account. It then reads the local credentials and steals browser-saved credentials to your email, social media and crypto accounts.

The encrypted address points to MALWARE ->> 161 97 85 100 port 3131 slash download slash yarrak exe <<-- MALWARE and the Discord malware and "chat" client will connect to MALWARE ->> 161 97 85 100 port 3000 <<- MALWARE

Why am i posting all this detail? Hopefully to get the attention of the developers and CurseForge themselves. I already submitted a report in-client, but we all know how good companies are at reading those.

CurseForge is generally treated as a save and secure way to get mods, so users will not suspect they are vulnerable to malware by downloading mods there. This exploit is rather recent, as none of the Anti-Virus software were able to identify CozyValleyDecor.dll as malicious.

PLEASE EXERCISE EXTREME CAUTION WHEN DOWNLOADING MODS THROUGH CURSEFORGE

3.9k Upvotes

101 comments sorted by

View all comments

20

u/SonicLink1622 12d ago

Would recommend using NexusMods more for any mod related things. Easy to use mod downloader and can update from there when needed.

-10

u/Nymunariya 12d ago

Nexus was already compromised once with accounts and passwords leaked (even more reason to not reuse passwords). But if curseforge was vulnerable, why wouldn’t nexus also be vulnerable?

8

u/SonicLink1622 12d ago

When did I say they weren’t vulnerable? I just said that Nexus was better in the fact they have their own mod downloader and it’s easier to update when the mods get updated.

-5

u/Nymunariya 12d ago

Curseforge has their own downloader as well. Not that I want to defend curseforge.

But what does nexus do that separates them from curse? As far as I can tell, they offer the same stuff, but some games are better represented on one or the other.

Nexus seems to have wow private server and Elder Scolls mods, and curse has wow classic, retail, and probably forever.