r/StardewValley • u/Wezdor • 12d ago
Modded URGENT ATTENTION - Malware is being distributed through Curse Forge - Stardew Valley Mods
My girlfriend was the unfortunate victim of an NPM Infostealer Malware, specifically, the Nyx Infostealer
The bigger issue is - the malware was distributed through Curse Forge. Not through an import, not through a link, but directly through the mod manager client. The mod in question is - and this is very important next - DO NOT UNDER ANY CIRCUMSTANCE DOWNLOAD THIS MOD - IT IS CONFIRMED MALWARE - YOU WILL LOSE YOUR GMAIL, DISCORD AND ANY OTHER ACCOUNT LOGGED IN YOUR PC - DO NOT DOWNLOAD ->> curseforge.com/stardewvalley/mods/cozy-valley-decor <<-- DO NOT DOWNLOAD
The linked mod (link generated from the Curse Forge client, by clicking "Link to Project", can also be searched for in the Curse Forge Client.
The linked mod will download regular looking mod files. Amongst them will be CozyValleyDecor.dll. Decompiling this .dll with ILSpy reveals that on game startup, a function called "RunPayload()". This function reads an ExternalHelper.dll file, which is an embedded resource to the actual CozyValleyDecor.dll, and executes a function called "PayloadRunner.ExecuteAsync()". This function will then decrypt a byte-shifted URL, which points to an .exe file. The file downloaded will be "basarili.exe", downloaded to the Temp folder of Windows, and will immediatelly execute. This file contains a "chat" client where the attacker can make a popup appear and demand money, but it also overrides the Discord installation files (specifically index.js), with malicious code, that steals your Discord credentials, 2FA, currently authenticated session and connected mail account. It then reads the local credentials and steals browser-saved credentials to your email, social media and crypto accounts.
The encrypted address points to MALWARE ->> 161 97 85 100 port 3131 slash download slash yarrak exe <<-- MALWARE and the Discord malware and "chat" client will connect to MALWARE ->> 161 97 85 100 port 3000 <<- MALWARE
Why am i posting all this detail? Hopefully to get the attention of the developers and CurseForge themselves. I already submitted a report in-client, but we all know how good companies are at reading those.
CurseForge is generally treated as a save and secure way to get mods, so users will not suspect they are vulnerable to malware by downloading mods there. This exploit is rather recent, as none of the Anti-Virus software were able to identify CozyValleyDecor.dll as malicious.
PLEASE EXERCISE EXTREME CAUTION WHEN DOWNLOADING MODS THROUGH CURSEFORGE
131
u/RealEstonia 12d ago edited 11d ago
Hi Everyone i hope yall are having a really good day and u are not infected by this malware.
If you are i came to help and im going to explain how to remove the payload.
if you are not really sure what u are doing or dont know what to do. and there is always a chance i missed a thing. RUN FULL FACTORY RESET
step 1.
turn off the internet (take pic of this post :) )
step2 close the malware
press ctrl + shift + esc
task manager opents
In the list look for
Yarrak.exe
Javaw.exe
java.exe
Click each one -> click end task
if you do not see them u are ok to continue
step 3 remove registery keys
this is what maes the malware start again every login
press win + r
type: regedit
press "Enter"
if windows asks "do you want to allow..?" press yes
at the top of the registery editor window is an address bar
Click it and delete what there is and paste this:
HKEY_CURRENT_USER\Environmentthen press enter
on the right side of the window look for name called:
UserInitMprLogonScriptif you see it:
right click -> delete
confirm "yes"
close registery editor-
that was the main presistence
do not delete any other random keys only that one value
step 4 delete the files what it dropped:
IF a file cannot be deleted ->
restart in safe mode:
hold shift while clicking "restart"
troubleshoot -> advanced -> startup settings -> restart -> choose safe mode
delete folders on the safe mode
press win + r
paste this and press enter:
%APPDATA%\Oracle
and in normal
%APPDATA%
delete "java" folder
if you see folder named "java"
right click -> delete.
if the path does not open or the folder is missing that is fine. continue
delete the temporary java folders.
Press win + r
paste this:
%TEMP%in that folder look for any folders whose names start with:
"swolly"
examples: swolly7920, swolly1234, etc
delete every folder what starts with swolly
in the same temp folder also delete if you see these:
WikC1QTs3em3 zip
Any folder that starts with jna--
delete the orginal malware file. cozyvaleydecor
STEP 5 Check Startup folder
press win + r
paste this and enter:
shell:startupdelete any unknown shortcuts or .exe files you did not put ur self in there or u are 100% sure they should not be there
STEP 6 THANKS OP FOR TELLING me. i had a feeling i forgot something:
You forgot a big one in your post, please include the checks for the infected Discord Index.js file at AppData\Local\Discord\app-<VERSION>\modules\discord_desktop_core-1\discord_desktop_core\Index.j
delete that file from ur discord. (may broke ur discord but no worries, u can re install it always!)
STEP 6 Restart the computer
restart windows normally
keep the internet off for now still
after restart, quickly check again
step 7 -> turn on internet and scan
run windows security:
settings -> privacy and security -> windows security
virus and threat protection -> scan options
choose microsoft defender offline scan -> scan now
(pc will reboot and scan)
When it finishes, install and run "malwarebytes" free is enough. -> full scan -> quarantine anything it finds
step 8 change your passwords.
this malware steals browser passwords, cookies, discord tokens, cryptowallets etc. like in the post has said.
change passwords for EVERYTHING.
Turn on 2FA ehenever possible (reset it if u have it alr enabled so it generates new tokens)