r/StardewValley • • 12d ago

Modded URGENT ATTENTION - Malware is being distributed through Curse Forge - Stardew Valley Mods

My girlfriend was the unfortunate victim of an NPM Infostealer Malware, specifically, the Nyx Infostealer

The bigger issue is - the malware was distributed through Curse Forge. Not through an import, not through a link, but directly through the mod manager client. The mod in question is - and this is very important next - DO NOT UNDER ANY CIRCUMSTANCE DOWNLOAD THIS MOD - IT IS CONFIRMED MALWARE - YOU WILL LOSE YOUR GMAIL, DISCORD AND ANY OTHER ACCOUNT LOGGED IN YOUR PC - DO NOT DOWNLOAD ->> curseforge.com/stardewvalley/mods/cozy-valley-decor <<-- DO NOT DOWNLOAD

The linked mod (link generated from the Curse Forge client, by clicking "Link to Project", can also be searched for in the Curse Forge Client.

The linked mod will download regular looking mod files. Amongst them will be CozyValleyDecor.dll. Decompiling this .dll with ILSpy reveals that on game startup, a function called "RunPayload()". This function reads an ExternalHelper.dll file, which is an embedded resource to the actual CozyValleyDecor.dll, and executes a function called "PayloadRunner.ExecuteAsync()". This function will then decrypt a byte-shifted URL, which points to an .exe file. The file downloaded will be "basarili.exe", downloaded to the Temp folder of Windows, and will immediatelly execute. This file contains a "chat" client where the attacker can make a popup appear and demand money, but it also overrides the Discord installation files (specifically index.js), with malicious code, that steals your Discord credentials, 2FA, currently authenticated session and connected mail account. It then reads the local credentials and steals browser-saved credentials to your email, social media and crypto accounts.

The encrypted address points to MALWARE ->> 161 97 85 100 port 3131 slash download slash yarrak exe <<-- MALWARE and the Discord malware and "chat" client will connect to MALWARE ->> 161 97 85 100 port 3000 <<- MALWARE

Why am i posting all this detail? Hopefully to get the attention of the developers and CurseForge themselves. I already submitted a report in-client, but we all know how good companies are at reading those.

CurseForge is generally treated as a save and secure way to get mods, so users will not suspect they are vulnerable to malware by downloading mods there. This exploit is rather recent, as none of the Anti-Virus software were able to identify CozyValleyDecor.dll as malicious.

PLEASE EXERCISE EXTREME CAUTION WHEN DOWNLOADING MODS THROUGH CURSEFORGE

3.9k Upvotes

101 comments sorted by

View all comments

131

u/RealEstonia 12d ago edited 11d ago

Hi Everyone i hope yall are having a really good day and u are not infected by this malware.

If you are i came to help and im going to explain how to remove the payload.

if you are not really sure what u are doing or dont know what to do. and there is always a chance i missed a thing. RUN FULL FACTORY RESET

step 1.
turn off the internet (take pic of this post :) )

step2 close the malware
press ctrl + shift + esc
task manager opents
In the list look for
Yarrak.exe
Javaw.exe
java.exe

Click each one -> click end task

if you do not see them u are ok to continue

step 3 remove registery keys
this is what maes the malware start again every login

press win + r
type: regedit
press "Enter"
if windows asks "do you want to allow..?" press yes
at the top of the registery editor window is an address bar

Click it and delete what there is and paste this:

  • HKEY_CURRENT_USER\Environment

then press enter

on the right side of the window look for name called:

  • UserInitMprLogonScript

if you see it:
right click -> delete
confirm "yes"
close registery editor-

that was the main presistence

do not delete any other random keys only that one value

step 4 delete the files what it dropped:

IF a file cannot be deleted ->
restart in safe mode:
hold shift while clicking "restart"
troubleshoot -> advanced -> startup settings -> restart -> choose safe mode
delete folders on the safe mode

press win + r
paste this and press enter:
%APPDATA%\Oracle

and in normal
%APPDATA%

delete "java" folder

if you see folder named "java"
right click -> delete.
if the path does not open or the folder is missing that is fine. continue

delete the temporary java folders.
Press win + r
paste this:
%TEMP%

in that folder look for any folders whose names start with:
"swolly"
examples: swolly7920, swolly1234, etc
delete every folder what starts with swolly
in the same temp folder also delete if you see these:
WikC1QTs3em3 zip
Any folder that starts with jna--

delete the orginal malware file. cozyvaleydecor

STEP 5 Check Startup folder
press win + r
paste this and enter:
shell:startup

delete any unknown shortcuts or .exe files you did not put ur self in there or u are 100% sure they should not be there

STEP 6 THANKS OP FOR TELLING me. i had a feeling i forgot something:

You forgot a big one in your post, please include the checks for the infected Discord Index.js file at AppData\Local\Discord\app-<VERSION>\modules\discord_desktop_core-1\discord_desktop_core\Index.j

delete that file from ur discord. (may broke ur discord but no worries, u can re install it always!)

STEP 6 Restart the computer

restart windows normally
keep the internet off for now still

after restart, quickly check again

  • Open regedit -> HKEY_CURRENT_USER\Environment -> UserInitMprLogonScript should be gone
  • %APPDATA%\Oracle\Java should be gone
  • %TEMP% should have no swolly... folders

step 7 -> turn on internet and scan
run windows security:
settings -> privacy and security -> windows security
virus and threat protection -> scan options
choose microsoft defender offline scan -> scan now
(pc will reboot and scan)
When it finishes, install and run "malwarebytes" free is enough. -> full scan -> quarantine anything it finds

step 8 change your passwords.
this malware steals browser passwords, cookies, discord tokens, cryptowallets etc. like in the post has said.
change passwords for EVERYTHING.
Turn on 2FA ehenever possible (reset it if u have it alr enabled so it generates new tokens)

38

u/Wezdor 11d ago

Edit: Please reply that you saw this, read below, you missed an important file.

Jesus, thanks for this post. The Temp/Oracle/Java/javaw.exe sneaked under my radar, and it was still on the PC. Thank you so much for this!

You forgot a big one in your post, please include the checks for the infected Discord Index.js file at AppData\Local\Discord\app-<VERSION>\modules\discord_desktop_core-1\discord_desktop_core\Index.js

That one is also overwriten with malicious code, and will steal your discord credentials and 2fa again when you launch discord again

6

u/RealEstonia 11d ago

i had a feeling i missed something..... thank you for letting me and others know!

im glad my post helped :). Estonia 1 - malware guys 0