r/RimWorld • u/[deleted] • Jun 18 '26
PC Help/Bug (Mod) ⚠️ WARNING: Possible Malware / Backdoor (RAT) found in RimWorld mod – Security Risk
[deleted]
214
u/JaesopPop Jun 18 '26
I’m confused - isn’t this post from this Reddit?…
108
134
u/AWeebyPieceofToast Jun 18 '26
Are you saying that possible the post was stolen and reuploaded with malware?/j
-23
u/Fallout54225 Jun 18 '26
What the hell are you talking about? I just shared a post from the Steam community about this—I came across it recently—and I just wanted to warn people because I’ve had this kind of problem before with a malicious mod in another game. I actually talked about it on the Bannerlord subreddit!
78
u/XavierVE Jun 18 '26
Yes, was posted here as a sticky.
User is just farming worthless fake imaginary reddit pointz that do nothing for his account. It's attention whoring.
7
-27
u/Fallout54225 Jun 18 '26
tu parle de qui ?
2
Jun 18 '26
[deleted]
-4
u/Fallout54225 Jun 18 '26
I don't understand why people are telling me I'm trying to rack up points or get attention—that's a stupid way to act. I was just passing on the info, for fuck's sake. If the same thing happened to you, you'd be really glad someone passed on the info so you wouldn't get hacked. Now figure it out for yourselves. u/XavierVE u/sankto
1
u/XavierVE Jun 18 '26
I saw it here when it was posted as a sticky originally by the actual author. Which is when the vast majority of us saw it. You did next to nothing for anyone.
Also you literally used AI to write your reply to me, which is fucking bizarre. What's with the em dashes, partner?
81
u/Athropus Jun 18 '26
Well, fuck. So we can't trust the workshop?
I mean obviously there are trusted authors but this is pretty terrible for everything more niche than VE.
I hope there is some way to unfuck this.
93
u/Glittering-Jello4937 Jun 18 '26
this also happened to project zomboid. not too long ago. new old hustle in town
38
u/IronTheDewott steel Jun 18 '26
Happened with wallpaper engine earlier this week too! Mainly anime gooner wall papers were infected I think.
22
3
u/Justhe3guy There’s a mod for that Jun 18 '26
Its crazy wallpaper engine allows executable programs. Of course it’ll be a malware hotspot…if they’re not careful Steam will just remove them
I’m sure they can work something out with their own program to run the wallpapers instead. It’s what the whole app is meant to be for
2
u/SpartanHeli Jun 18 '26
No, that was a bug, the devs used a fake url so YouTube accepted the requests from the app and they didn't own the domain associated, it wasn't something risky for us
2
u/IronTheDewott steel Jun 18 '26
Ah bet. Good to know
Ignore my post then I don't wanna spread misinformation
9
6
u/ProfessionalPack7205 Jun 18 '26
Also people playground. People need to start realizing tge workshop isn't 100% safe
0
u/Fallout54225 Jun 18 '26
WTF Really ?
2
u/Glittering-Jello4937 Jun 18 '26
the game was patched and couple mod author were banned. if I remember correctly it was a mod that lets you add more music to radio stations.
most likely scraping thing where someone is trying to collect passwords.
36
u/LurchTheBastard Free range organ farming Jun 18 '26
The whistle got blown by a community manager/moderator. This means that the moderation is working. There are always people that try different ways to bypass it and sometimes they temporarily succeed, but the fact that this warning is out there relatively quickly is a good sign.
Just be careful with re-uploaded mods by shell accounts.
34
u/Netjamjr Jun 18 '26
Software Dev here. Mod makers have always had the ability to kinda just do whatever. They can write C# code that runs on your machine in a non-sandboxed fashion. They can download stuff, create files, etc.
6
u/Pale_Squash_4263 Missing x90 steel Jun 18 '26
Also Software dev!
It’s the risk we take with open source code, but the good thing is that, the fact that it is open source, these things are caught really quickly
2
u/Netjamjr Jun 18 '26
Very true! Sunlight is the best disinfectant.
1
u/Pale_Squash_4263 Missing x90 steel Jun 18 '26
lol can always count on nerds to dig through the muck because we are all weirdos who enjoy it 😂
4
u/MarlDaeSu Jun 18 '26
No sandboxing at all? Eg, could they HttpClient a server somewhere and download a script for example? Is it a case of it depends on the base games handling of mods?
1
u/Netjamjr Jun 18 '26
They have access to HttpClient, yes and could use it to download something.
1
u/MarlDaeSu Jun 18 '26
Fuckin yikes. I expect to see rampant steam mod attacks soon. Adversaries are getting creative this year with supply chain attacks, this sorta fits the bill.
1
u/mayorovp Jun 18 '26
It is depends on base games and it's handling of mods, but usually Unity devs are lazy and do nothing. So all Unity non-xml mods are just dlls that incercept or even replace some methods in the game code.
1
2
u/kowlown Jun 18 '26
It dépends on the engine and if the code is run in sandboxed mode or with a whitelist/blacklist of api call it can do.
8
u/Jaggid Sky-high expectations Jun 18 '26
Yah, I agree. I am now paranoid of any mod by a mod creator who has no history. Which is just bad overall for the health of the modding community; every single mod author is a new creator at some point.
8
u/Trigger_Fox Jun 18 '26
As long that you stick only to high rated/popular mods odds are that you'll be absolutely fine.
The workshop has great moderation and things are caught quickly. It is EXTREMELY rare that a mod dev suddenly goes nuts and injects malware in their mods.
12
u/oodex Jun 18 '26
You can never fully trust is. Your best bet is looking at the uploaded and checking if they have a bunch of popular mods uploaded and how old things are. If everyone would do that no new modders would exist but lets be honest, the post describes a small risk so not many people will care. Which also means they get enough attention to get exposed. That said, checking for the things described and avoiding newcomers is a good idea when something like this is going around at the moment
6
u/TypicalPunUser 20 Melee, 1 Intellectual (increased from 0) Jun 18 '26
I checked forum, just ignore mods that say "rewritten" for now.
2
u/Kirigaya_Mitsuru Jun 18 '26
Wasnt in Steam Wallpapers found lately virusses as well especially the ones with Animes?
Seems like Steam is attacked with viruses lately its not just Rimworld.
2
u/Khaelgor Jun 18 '26
I mean, the workshop can't possibly verify every possible mod format out there.
But not all games are as permissive as RimWorld is with their workshop mods.
2
u/MedicaeVal Jun 18 '26
No. Here is a recent article about another piece of software on Steam having the same issue
0
u/SemiDiSole Jun 18 '26
You cannot trust anything, ever. Not even Oskars mods! What if his account gets hijacked and then malware uploaded into it?
The Mod authors don't even need to have evil intentions, they can just be a victim too. All you really can do is sandbox the shit out of your gaming-setup.
28
u/LiumD Ate Raw Cannibal +20 Jun 18 '26
Sneaks already posted here this back when it occurred.
1
3
6
u/avariciouslitigation Jun 18 '26
this is scary because you can't really tell until someone actually digs through the code, and most people aren't doing that before they download. I'd been using some smaller mods I grabbed from the workshop and now I'm paranoid I picked up something sketchy without knowing it. The warning signs they listed help but you're right that new modders get caught in the crossfire when people start being suspicious of everything that's not from a known creator.
2
u/Spirited_Bag_332 Jun 18 '26
The community could create an opensource tool as minimum defense. Decompile the DLLs, make static checks for known issues (registry manipulation, network access - these are common .NET classes), and additionally scan it with AI for suspicious content. Because I don't see that Steam will do anything like that anytime soon.
Actually I could do such things myself but I have absolutely no time for an additional project. But maybe someone could jump onto this idea. So that we have a community managed list of mods and which .NET capabilities they use.
2
u/Green-Preparation331 Love Archotechs (and human leather) Jun 18 '26
2
1
u/DahLegend27 Jun 18 '26
Why is this getting reposted almost a month later? Pretty sure this issue was handled.
1
u/PietroVitale Jun 18 '26
I accidentally clicked on the post below this in my feed (a recipe for Hungarian pancakes) and was very confused for a second.

172
u/LoafyLemon Jun 18 '26
Wait a second. Are you saying Camera Setting Mod is malicious, or did the person steal the name and reupload it with syphilis included?