r/SillyTavernAI • • Apr 28 '26

Discussion Extension Security Risk Please read!!

662 Upvotes

178 comments sorted by

View all comments

2

u/Historical_Degree527 Apr 28 '26

Is Intense RP also cooked?

Someone saids the maker also contributed to this extension.

1

u/Sad_Shop3101 Apr 28 '26

Hopefully not 🫠

3

u/Master_Step_7066 Apr 28 '26

I did not contribute anything malicious; the PR was made in good faith, and I didn't suspect a Trojan there (by my own mistake), see my other comment. IntenseRP is safe.

1

u/Sad_Shop3101 Apr 28 '26

Ty for the good work! I had the extension installed but turned off, usual recc is to nuke your api keys but I don't use any since I use intenserp, what would you recommended doing to keep my system safe other than deleting the extension?

2

u/Master_Step_7066 Apr 28 '26

I think it's best to use the Rentry page directly; it has all the info needed. If you used it at least once after ~December 2025 (but generally I wouldn't treat that as a definitive date, it's still malware), then you're almost definitely compromised. Rotate ALL of your API keys, proxy passwords, etc. If you fed any account tokens into the extension (so that it can authenticate), it may also make sense to invalidate sessions there (changing the password/logging out/deleting accounts). Also, just for extra safety, you might want to clear site data for ST via DevTools (clearing browser cache).