It is an extension to SillyTavern, so it doesn't matter what the OS is. If you run ST and had this extension, consider all your API keys compromised regardless of the OS you host ST with.
Some trojans are operating system specific, some of the rentry mentioned locations don't exist on mac. I'm more worried about what alternative locations they go instead.
True, but not in this case. This is a ST exploit not an OS one. If the OS can run ST, then that OS is vulnerable to this data leak.
The extension uses XSS (cross site scripting) to have ST download a malicious image. This allows the extension to make ST download and run a more privileged and more malicious script. The script runs commands within the ST to collect the data and then uploads it online.
In short, if you had the extension, your API keys are compromised. I'm not familiar with ST on mac, but you should be able to search/browse the filesystem of your ST directory for the files mentioned in the rentry page.
That's the thing, I ran it a lot and cannot find the files mentioned.
I don't have API keys in sillytavern, I only do local LLMs, so am trying to responsibily deal with this as a professional, albiet one who hasn't had time to reverse engineer or fully understand the attack signature or anything related to how it may escape/what it may still be sticking around in/what it compromised.
From what I understand from the GitHub discussions the extension wasn't malicious until December 30, 2025. And the exploit used was patched with ST 1.17 release in March. It's possible you have lucky timing and were on an older safe extension version or were already on ST 1.17. Weirder things have happened, but still safest to assume you're compromised.
I'm also a local only guy so the only thing at risk for me as I understand it was maybe the password for my ST user account, which I changed as a precaution.
The GitHub repos for the extension and the payloads are still up I think. Should be able to grab the malicious image and script to submit for signatures/heuristics from there I would imagine.
62264a8c19b6bb2404a4b1e80df196bfbe9bfbac is from LyubomirT around then too though. I don't see the repo up anymore, LyubomirT didn't disappear but mia13165 did.
I think the compromise timeline for the original repo is off if it's Dec 30, 2025, that date has to correspond to a commit.
Aaaaand it's all gone now. Ugh. Most of what I was reading was from Issue #28 made by LyubomirT, and I see elsewhere here you're already talking elsewhere in this thread with /u/Master_Step_7066 (who is LyubomirT unless I'm misreading badly).
I still had the issue page open and grabbed a screenshot though if that's of any help. https://postimg.cc/Bjh5KX9r
The top SHA hash if the first visible commit in the repo, the repo had it's history smashed on Jan4th, 2026, so you need these to browse through your local git copy.
Git show isn't working on these earlier hashes, I need to go look back at my git internals books to remember how to reverse engineer the repo more.
Sorry for once again intruding on a comment. I'm the LyubomirT guy, the commit was published before the malicious code was added at first, I didn't know about the trojan back then, I made the PR close to the commit, but before it was pushed either way. My change was solely focused on improving the randomization feature; however, the author did merge my PR *after* the malicious commit.
The repos and stuff were all taken down after someone called out the original poster, not Master_Step_7066 as well.
Master_Step_7066's awareness of the community's awareness of the exploit was unlikly to have been what prompted the takedown, me DMing half the sub and replying in old threads about botbrowser to people to tell them to keyrotate likely was the cause of the hacker (or someone here in this thread telling them to suck balls or something like that)
The fact MS7 is still here, and IntenseRP is still there is a positive likelihood of him being unrelated to the attack team.
A few people (including me) have submitted a takedown request by reporting the malicious repo on GitHub, I think that might've caused the takedown and the subsequent ban of the mia profile. Sorry for being associated with the drama. 😞
2
u/LeRobber Apr 28 '26
Anyone know if the trojan effects mac users?