#šŸ”„ļø±curseforge-support

1 messages Ā· Page 94 of 1

idle mango
#

As an infosec professional I concur with this statement

sterile kestrel
#

I'm not that far yet

#

Getting there though I need some certs

grand fox
#

What stages of the malware does the CF scanner detect?

candid needle
sterile kestrel
candid needle
#

i think

sage shore
#

I love how this is happening on the same day as the 1.20 update. yahoo

lament hearth
#

Should be right.

candid needle
grand fox
#

If it gets to stage 3, will it still be detectable through older stages?

idle mango
candid needle
grand fox
#

Is there any way to scan for stage 0?

lament hearth
#

It won't detect it if it is dormant. Requires you to run a file affected so that it can create the needed directory, I believe. Could be wrong.

idle mango
#

Got my CISSP 5 years ago I stopped maintaining it

sterile kestrel
grand fox
lament hearth
sterile kestrel
#

Or none were infected kind of a toss up given ongoing investigation

grand fox
#

I mean I’ve run every modpack I have and the directories were never created, luckily enough I don’t usually play premade modpacks

crimson vale
#

For me it was enough to just reset my PC completely and reinstall everything (except any Mod Launcher for now). Will stop playing for a while now

grand fox
candid needle
#

i don't think it should be there

sterile kestrel
candid needle
#

where is it located tho, i would look for myself

lament hearth
muted current
#

It’s also pretty safe to say that if you didn’t download any of the compromised mod packs/ mods (mostly lunar pixel projects) yesterday you are in the clear. There were some misc malicious mods circulating for the last 2 months but I don’t think they picked up a ton of downloads.

sterile kestrel
#

Stage 0 can't execute mainly because the C&C is offline, which could change

grand fox
#

What is c&c

dusty grove
sterile kestrel
# grand fox What is c&c

Command and control server. Essentially the server being used to infect the machines and extract the info

#

It's how it "phones home" so to speak

lament hearth
#

I am hoping the way I did this works.

muted current
#

Could stage 0 mods be activated at this point though? Considering the server was taken down by the server provider

grand fox
#

It’s annoying how this all came up the day of an update when everyone’s gonna want to play new mods NOOO

lament hearth
#

So I have to run the detector once in a while, just in case.

sterile kestrel
lament hearth
#

Yeah, lots of traffic? Perfect day to spread malware.

crimson vale
sage shore
#

Wait, does the mods on Modrinth have malware or is it just on Curseforge?

grand fox
sharp stream
#

O shit it's the seventh 1.20 is coming out

candid needle
lament hearth
sage shore
crimson vale
sage shore
sharp stream
muted current
#

Do we have the tools to scan for stage 0 yet?

candid needle
#

i think no

#

same with stage 3

sterile kestrel
acoustic cedar
#

What's the difference between stage 1,2 and 3?

weary hazel
#

If the current scans say you’re in the clear, then just wipe your mods as a precaution and wait until mods are confirmed clean once again to download them back.

muted current
#

Stage 3 is bad stage

lament hearth
#

You might not feel a need for it, but I would just take a torch to your installed mods if Stage 1 hasn't activated.

#

Should remove all possible malicious files.

acoustic cedar
#

Ftb is safe

#

Right

weary hazel
muted current
#

Excuse the language but this so fucked…..

sterile kestrel
#

Stage 3 is the point to where your credentials could be( or depending on timeframe) have already been stolen. Stage 1 is establish persistence(infect the other jars)

weary hazel
sage shore
#

I think that I am going to play FORTNTIETEHGH (Jk, gonna play some tf2)

lament hearth
#

It is a pretty good shot by them. This was the perfect time for a malware attack considering the 1.20 update.

weary hazel
#

Stage 2 is when it runs on startup and leaves the files that the current scans find.

timid minnow
gaunt gale
#

Did they put the detection tool out already?

sterile kestrel
#

All it took was one slip-up with a high profile account lol

weary hazel
lament hearth
#

Detection tools are out

sterile kestrel
#

Or it was intentional. Who knows

lament hearth
#

Check 'em out.

gaunt gale
sterile kestrel
#

Or the hackmd

weary hazel
sterile kestrel
#

News one has the one deved by CF. The hackmd has some scripts that were developed last night as it was discovered

sage shore
weary hazel
#

Since it’s been out for a few months it’s likely that the increase in modding with the update just produced enough traffic for it to be found.

sterile kestrel
#

Really shows the need for code signing tbh. Apparently CF tried before?

weary hazel
#

More people watching leads to a higher likelihood that it’s caught

sage shore
sterile kestrel
weary hazel
#

It’s unknown if the malware creator edited timestamps but supposedly the last 4 months are questionable with an increase in the past several weeks.

acoustic cedar
#

Anyways i can download overwolf right

sterile kestrel
#

Even then it wasn't actually noticed until lunar went wait a minute that's not us who logged in lol

quaint horizon
#

how do i update curseforge profiles from 1.19.4 to1.20

weary hazel
#

That’s why CF is scanning all of the mods on their site now since it’s not an issue on their side except maybe security.

pallid magnet
#

really dumb question: do we need to have curseforge downloaded (since i mainly download from the website) for the tool to work or

gilded crag
#

is it safe for me to launch my modpacks?

pallid magnet
sterile kestrel
indigo locust
#

its safe for download and update mods ?

silk wind
#

how do you use the detection tool?

sterile kestrel
sterile kestrel
weary hazel
#

Step 1: scan. Step 2 (if no malware): delete your mods and wait until all clear. Step 2 (if malware found): wipe everything and you should clean install windows to be 100% safe.

indigo locust
#

i thought that was just some mods and that the team already removed them
its not that ?

lament hearth
#

Nope, there are more

sterile kestrel
weary hazel
#

They removed the mods they knew about but not every mod is known

lament hearth
#

We just don't know which ones.

#

As mentioned, just torch all the mods if Stage 1 has not come to pass.

silk wind
#

how do you use the detection tool??

#

how

faint walrus
#

download it and double click the file

silk wind
#

it just opens

plucky cliff
lament hearth
#

Do NOT take the risk of using any modpack that is possibly affected by malware.

plucky cliff
#

So no, it's not only some mod teams

rancid shadow
#

hello i had a question. does anyone know a minecraft server hosting site were i can host a free modded server for me and my friends?

weary hazel
#

Stage 1 is what spreads it among all of your .jar files so if you got 1 that had the malware (even if we don’t know it does yet) they could all be infected.

sterile kestrel
gilded crag
rancid shadow
# slow ruin Aternos

yea i know but the mods i wanted to play got deleted from that site so do you know any others?

silk wind
sterile kestrel
indigo locust
gilded crag
silk wind
gilded crag
sterile kestrel
plucky cliff
#

It's the third link in the news channel btw

idle skiff
#

if i downloaded a worldedit 7 days ago would i be safe?

silk wind
#

and theres no exe in the folder

plucky cliff
weary hazel
#

Stage 2 is when you’re past the point of no return and it allows stage 3. The scanner only scans for stage 2 so delete all mods anyway.

plucky cliff
#

Check to be sure

idle skiff
#

is worldedit infected?

silk wind
#

alr im good

#

whew

sterile kestrel
plucky cliff
sterile kestrel
#

Just any known infected mod?

plucky cliff
#

Idk but that's what the tool was specifically for. If you read through the thing they explained how to search for stage1 &2 and they were making the tool to detect stage0 which is now out

weary hazel
sterile kestrel
#

Huh I thought it was the other way around

sterile kestrel
#

S1 and 2 were detectable 0 was not

#

Then again

tidal zenith
#

Hi does any one know why Iris is crashing my minecraft? I use a curseforge launcher

sterile kestrel
#

Now I'm rethinking that it makes sense lol

weary hazel
sterile kestrel
#

I'm working(on lunch) so do not have alot of time to absorb new details since last night

weary hazel
#

Alright good

faint walrus
#

could go to the github and take a look at the source code

plucky cliff
#

Which is the nekodetector people have been using

ionic gulch
#

Wait if I haven’t touched my craptop since may 16 I’m safe?

plucky cliff
sterile kestrel
#

Oh nice

ionic gulch
sterile kestrel
#

Looks like the tool appears to be complete. I'm on linux haven't found directories but will run then

weary hazel
plucky cliff
#

Even then I would to be careful lol it doesn't take long

#

To run the tool

sterile kestrel
plucky cliff
#

I believe this was finished recently

ionic gulch
#

I will have to run it when I get back home in 3 days. I gotta go through an 8 hour flight in 64 hours

plucky cliff
#

I ran it a couple time and it came back clear luckily so seems like it never was on my pc

grand fox
#

If I never had any of the directories is it safe to say that the virus at least hasn’t gotten past stage 0 if it’s on my pc

sterile kestrel
#

When an IT community get riled up on security, shit gets done lol

sterile kestrel
tough ridge
digital roost
#

How long is this going to last?

slow ruin
#

how informative!

sterile kestrel
grand fox
lament hearth
#

Yeah, torch your mods to be safe I would think, even with a detector for St0.

tough ridge
#

Does anyone know who did the hack?

lament hearth
#

Nope

digital roost
plucky cliff
grand fox
plucky cliff
#

Ik before it was better to because we couldn't detect 0 only 1 and 2

tough ridge
#

You can’t skip stages, it must go through stage 0

weary hazel
#

CF claimed everything could be scanned in around 12 hours

tough ridge
#

To get to next stages

sterile kestrel
#

If we can reliably detect stage 0 then there isn't a need to torch the mods if it doesn't find anything

grand fox
#

Is anyone working on a scanner for stage 0?

plucky cliff
sterile kestrel
#

Stage 0 scanner ^

grand fox
#

I saw that, just dk how to run it

tough ridge
#

Does the curseforge one scan stage 0?

grand fox
#

No

sterile kestrel
lament hearth
sterile kestrel
grand fox
#

Does the cf scanner look for anything past stage 1?

lament hearth
#

Yes, S2

sterile kestrel
tough ridge
#

So cf scanner scans stage 0, 1, and 2?

sterile kestrel
#

May need to include absolute path to the jar file

sterile kestrel
tough ridge
#

Alr thanks

grand fox
lament hearth
#

CF does S1 and S2. From what we know, Neko detector does St0

#

Stage 3, I don't know.

weary hazel
#

Is there a video or step by step guide on the neko scanner?

lament hearth
#

No clue.

river hill
#

is it safe to play sky factory 4 currently?

weary hazel
#

Define safe

lament hearth
#

No mods are safe atm. Use the detector beforehand if you are going to go ahead anyway.

sterile kestrel
#

And after ^

umbral hedge
#

how do i download this nekodetector? github is too confusing for me

twilit heron
#

I am currently trying to download the Detector Tool from both GitHub and the CurseForge Support site, and both locations I am prevented from downloading due to the file saying "virus detected". Is there a fix for this?

sterile kestrel
#

Browser security settings most likely

lament hearth
#

There are no releases of the detector for me just yet.

twilit heron
#

Turning off the browser security still didn't allow the download to proceed

grand fox
hearty chasm
#

how do i use the detection tool?

umbral hedge
#

i can't download nekodetector guys there is no option in the github

umbral hedge
hearty chasm
#

Download as a zip

#

Then extract

grand fox
blissful dagger
hearty chasm
grand fox
hearty chasm
#

You can turn off your windows anti virus temporarily if you feel safe enough to do that

light drift
#

so like can i download any mods like security craft, scp overload, scp restoration and mrcray mods without getting a virus? or are they also unsafe?

sterile kestrel
#

Usually there is an instance of run anyway on expand

grand fox
#

i did that

blissful dagger
#

I’m dead

grand fox
#

and it installed what do i do now

sterile kestrel
light drift
#

ok

#

crap

sterile kestrel
#

You do so at your own risk. If you MUST download then you should run the detection tools before and after running them at minimum

blissful dagger
#

What about mobile

umbral hedge
stone lintel
#

Why can i load Fabric/Vanilla minecraft but not forge?

#

it gives me an error code when i try to

river hill
#

if i have not updated a mod can i play it?

static rock
stone lintel
#

i keep getting this error code when i try load up forge minecraft why is it?

grand fox
sterile kestrel
sterile kestrel
hearty chasm
static rock
hearty chasm
#

would get it if opera wasnt slow as shit

stone lintel
#

Can someone help me please

split crow
#

Hello. I have question about these malware mods.

I uninstalled CurseForge and then ran detection tool. It said there is no any malicious files, but I have doubts if I did something wrong.

teal trout
#

Hey guys, how to run the detection tool ? there's no .exe

split crow
teal trout
#

ok

light drift
#

if i downloaded mods like last week and now deleted them and if i would delete curse forage for some time, am i safe?

summer junco
#

@teal trout please avoid using slurs

split crow
earnest fiber
#

curseforge itself is safe, correct?

#

the application

tough ridge
#

Yes

earnest fiber
#

alright

light drift
#

but like i deleted them so like they should be gone right

dim blade
#

Hello, I've run detection tool, manual check and also blocked the IP that was giveen (just didn't edit host files), yet, i cannot find "%LOCALAPPDATA%\Microsoft Edge"

split crow
#

So, should I have CurseForge installed to use detection tool?

earnest fiber
#

nope

#

works without it too

split crow
#

Good

earnest fiber
#

you just need to run the executable

#

and click Scan

dim blade
#

Thank you, going to delete the files now

split crow
cyan plinth
#

just wondering is mods rn on the platform are safe or not

earnest fiber
dim blade
#

Found nothing

light drift
#

wen did this start? i ran minecraft with the mods 2 days ago

cyan plinth
marble ridge
#

Hey! Question, was the modpack "Fabulously Optimized" affected?

earnest fiber
dim blade
#

Yet, my only doubt is, servers like Aternos are safe? Like, should I reset the server after all of this setles?

split crow
stone lintel
#

WHy do i keep getting this when i try to load up Forge Minecraft

earnest fiber
split crow
dim blade
#

It's instant

light drift
#

is the tool safe to use?

split crow
dim blade
light drift
#

wait wont windows protection just locate the virus?

broken badger
#

not always, it usally cant detect them

marble ridge
#

Wheres the actual bug detector file?

young sedge
#

what are these ?

earnest fiber
#

is there any way I can get curseforge to install mods that are on my computer already?

young sedge
#

help someone please tell me are those virus?

digital roost
topaz surge
#

no lmao, windows files.

tough ridge
young sedge
#

a mod please answer

steady cosmos
#

ntuser is user files

digital roost
#

seems russian to me lol

topaz surge
covert arch
#

is it safe to play a modpack i made a few weeks ago?

young sedge
#

can we ping a moderator?

topaz surge
#

why? I already told you what you posted is not malware

echo dagger
#

ive already ran the tool and didnt get the virus, is it still safe to use curseforge or not yet?

young sedge
#

i need to know if they are virus or not

topaz surge
#

It's not

lofty juniper
#

It means im right?

fathom trench
young sedge
#

i also run the code and didnt get anything

hearty chasm
#

Can't figure out the nekodecector

devout nimbus
young sedge
#

i dont have anti virus

topaz surge
#

It wouldn't help much even if you had an anti-virus as this is not detectable yet.

digital roost
topaz surge
#

bruh fuck off

young sedge
#

are you serious ?

covert arch
#

how do i use the detection tool, i downloaded it but dont know how to run it.

lofty juniper
topaz surge
young sedge
#

im confused, please dont joke about thing

pale pecan
#

is it fixted

earnest fiber
#

@young sedge are you russian?

hearty chasm
#

How do I run the neko detector ā˜¹ļø

calm plover
young sedge
hearty chasm
young sedge
#

i had russian folder before i guess

earnest fiber
#

if you know those folders they're fine, ntuser files are user files so they're also fine, did you run the detector program?

young sedge
#

i hope my warenty covers a reboot

topaz surge
tough ridge
#

Bro I think u got more malware than just this, unless u know those folders

fathom trench
young sedge
topaz surge
#

yeah that's the point of some viruses, you're not supposed to see it.

calm plover
#

yep looks normal

covert arch
#

how do i run the detector?

eternal slate
#

is launching atm8 safe rn on curseforge?

topaz surge
#

The world is a magical place isn't it

hearty chasm
#

@calm plover Am I not supposed to input the given command into powershell? There's no .exe

violet vortex
#

I am hoping someone can help me, I am getting an Exit Code: 1 when trying to load a 1.19.2 Forge modpack Cottage Witch version 1.19-1.14.9 . My GeForce driver is up to date, I just updated my Java yesterday. I have included screen shots of the drivers I have for both (incase I made an error somewhere) along with my latest.log file. I am out of ideas and would appreciate any help I can get. Please let me know if there is any other info I can provide to help you help me ā¤ļø

carmine galeBOT
#

Paste created of latest.log, uploaded by Fade_Alchemist.

calm plover
gloomy eagle
#

how to fix it

delicate wolf
#

Is it possible to get detector tool for Mac os as well. I know it wasn’t targeted but still, java is cross-platform

young sedge
#

i think i know what those russian folders are, i know a bit russian and country i live in use russian as second language,

digital roost
#

guys

slow ruin
digital roost
#

why is there no Litematica in minecraft mods?

hearty chasm
#

So is the curse detection tool 100% accurate?

steady cosmos
gloomy eagle
hard patrol
#

Also check the registry for an entry at HKEY_CURRENT_USER:\Software\Microsoft\Windows\CurrentVersion\Run
why does it not say what to look for

lofty juniper
#

where Do I put that command?

deep dome
#

i haven't downloaded anything from curseforge since i last formatted my pc, am i ok?

dim blade
deep dome
snow tinsel
#

Well the last modpack I downloaded was Seaopolis 2 a month or 2 ago. Hopefully I'm good

lofty juniper
#

thats right?

dim blade
#

As far as I know, it's not detectable by antivirus yet. Try to use the check up virus script that was given, and or check manually for any weird folders from the link given in news

hard patrol
#

yea, and what would the bad bit look like
like if u was infected, what would be there

dim blade
supple trail
#

the virustotal check for the detection tool shows that the file communicates with an IP that contains malicious content

proud saddle
#

I just play downcraft with my friends last week is it save?

dim blade
dim blade
crystal jackal
#

yo i'm trying to use gradlew.bat to scan my pc but it always closes should i be worried

slow ruin
#

that just builds Gradle

crystal jackal
dim blade
somber beacon
#

when can i use curse again

dim blade
#

Don't know, did you use the script or checked for the registry entry?

somber beacon
#

is it the website or the app?

rich jewel
#

I would wait until they finish the full scan of the site before downloading anything.

heady gyro
#

hopw to run the new tool?

dim blade
proud saddle
#

I scan it when i hear this problem ,it shows green word that mean i'm save or not

young sedge
#

does deleting and reinstalling windows system help

heady gyro
supple trail
dim blade
dim blade
proud saddle
tough ridge
#

Yes

dim blade
calm plover
young sedge
#

i hope creator of that brutally killed and tortured

dim blade
#

Official Prims Launcher Page

tough ridge
#

Is allthemods safe?

dim blade
#

Meant to take a screenshot with the address bar but jinxed it

#

Ah, it's said that is the malware origin IP, so blocking it serves as a deterrent: "@PandaNinjas has reported:
use your firewall to block outbound connections to 85[.]217[.]144[.]130, and modify your hosts file to include 0.0.0.0 files-8ie.pages.dev On linux add that line to /etc/hosts, on windows add that line to C:\Windows\system32\drivers\etc\hosts"

tough ridge
#

Let’s go to the owner’s house

wooden ice
#

Wascurseforge hacked????

dim blade
#

It explains the origin.

And I believe not since it seems to be offline

pine fossil
wooden ice
#

What does that mean if I have curse forge????

tough ridge
#

Is allthemods safe from the malware?

dim blade
sterile kestrel
wooden ice
#

Any minecraft or just curse forge??

dim blade
lament hearth
sterile kestrel
#

Should also note that atm8 is being very nonchalant and just saying "don't cry wolf" which irks me but thats neither here nor there

tough ridge
#

Alr thanks

somber beacon
#

i didnt touch app for the past two days

wooden ice
dim blade
#

Unninstall all your mods

sterile kestrel
dim blade
somber beacon
worthy mesa
#

I should uninstall all mods?

sterile kestrel
crimson vale
somber beacon
tough ridge
#

If the malware was found, should I reset passwords and stuff

sterile kestrel
# somber beacon ?

Something is getting lost in translation. You just said your computer was unusable...

dim blade
#

This applies if it hans't activated stage 0 as far as I understood

prisma magnet
sterile kestrel
young sedge
sterile kestrel
lament hearth
young sedge
#

are those malware?

lament hearth
somber beacon
pine fossil
#

Im not even gonna open my computer til this gets solved

sterile kestrel
# young sedge ?

Possible but hard to tell. I'm not seeing the ones it would normally find for it here

young sedge
somber beacon
lofty juniper
prisma magnet
#

i've run my antivirus + both detectors currently available just to be safe, and i did it right after the modpack started again, planning on doing it when i close the modpack just to be safe

would virustotal detect fractureiser if i were to say upload a mod jar to it?

young sedge
wooden ice
#

Wait so I can't even uninstall??????

somber beacon
#

the only thing i downloaded since april is dawncraft

young sedge
#

i decide to delete windows and reinstalled it

lament hearth
#

Change your passwords right after if at all possible

wooden ice
#

So what am I supposed to do right now?

prisma magnet
pine fossil
#

I would cry if my account got stolen

worthy mesa
#

The only way i found out about this is from AT Launcher, do they not have any warnings on curseforge?

prisma magnet
lofty juniper
lament hearth
wooden ice
#

Not to be paranoid or smth but what if the scan itself is a virus made by hackers that hacked the admins discord accountl

wooden ice
#

What if they did though?

digital roost
pine fossil
#

What if i dont have any of the mods installed that were infected

split mesa
crimson vale
lofty juniper
pine fossil
lament hearth
crimson vale
wooden ice
#

If I didn't run minecraft am I safe?

lament hearth
#

Pretty funny one too

pine fossil
lofty juniper
split mesa
#

If you downloaded or updated any mc mods through forge the files would be on your computer, you don’t have to run it

wooden ice
pine fossil
#

What if curseforge is running in the back ground

wooden ice
#

May 20th???? I did play at may 20th modded minecraft

split mesa
pine fossil
#

I played modded after may 20th…

earnest fiber
#

manual install supremacy tbh.

lament hearth
#

I am so glad CF is manual install

split mesa
#

Y’all just run the checker, it’ll solve your worries !

light panther
#

I play modded MC every day...

But the detector said there was nothing

pine fossil
#

Is the checker safe?!?!

worthy mesa
#

the checker is a bomb

wooden ice
#

this good right?

lament hearth
wooden ice
#

I think I did

pine fossil
lament hearth
#

Yes. If you play anyway, run the scanner afterwards as well

pine fossil
#

Last i played was RL craft and its like 1.12

wooden ice
#

Ah alright thank you I was scared (also just to answer the question the modpack was pixelmon)

wooden ice
nocturne sage
#

how do u run it

lament hearth
nocturne sage
#

can we still play our old ones?

pine fossil
#

how do i download the checker

sick canyon
#

where do i download the malware scanner?

lament hearth
wooden ice
primal salmon
#

I just heard about the mods. Before this was announced, I found 68 corrupted file on my computer. Which was odd because my mod list didn't change. I had to completely wipe my computer. However it is possible I still have the corrupted files in my external hard drive. I would like to speak to someone about investigating these files. I suspect that the corruptions were installed through an update.

lament hearth
outer sable
#

So stage 0 is what is hidden in the mod or plugin. It connects to a random server that is at the moment not online. This means that stage 1 can not be executed on your computer right now. It is however possible that the server comes back online eventually. So I would refrain from playing recent mods at the moment

ancient heath
#

i ran the gradlew thing on nekodetector. how do i actually tun the detector?

lament hearth
sterile kestrel
#

Doc has been changed they recently tried to stand up a new C&C

pine fossil
#

can someone send me the link to the scanner

ancient heath
#

ok,thank you.

narrow crow
#

As long as the provided scanner says that there's no stage 1/2, I'm good to delete any of my installed my mods, right?

outer sable
lament hearth
pine fossil
narrow crow
lost star
#

who do you use neko

lament hearth
pine fossil
#

time to torch mods and curseforge

lament hearth
#

CF itself is fine. Just the mods atm.

brave whale
#

So they're not stealing my information in stage0?

lament hearth
#

That happens in S3

pine fossil
#

Just torched all my mods and deleted all backup profiles and mods

lament hearth
restive cairn
#

S0 evokes S1; S1 evokes S2 and S2 evokes S3. In S3, they steal your data

lone atlas
#

does the malware scanner detect the malware in all stages

outer sable
misty patrol
#

i ran the scanner and it says nothing was detected

lone atlas
pine fossil
#

nothing was detected for me so i destroyed my mods and mod packs

misty patrol
lament hearth
restive cairn
#

So technically if you destroy everything mod related and run the scanner you should be fine.

lone atlas
outer sable
pine fossil
digital roost
#

I haven't launched curseforge for a while, and uninstalled it & all mods when i heard of the situation
also ran the script and detected nothing, am i good?

misty patrol
deep dome
restive cairn
outer sable
#

Yes, but only (that we now if) once it infected the system

lone atlas
pine fossil
#

just unistalled curseforge

misty patrol
restive cairn
outer sable
pine fossil
lament hearth
#

All traces of mod files need to be completely annihilated in order to minimize chances of infection, in my opinion. As long as they are not in an active state, you have your chance to torch them.

restive cairn
pine fossil
noble gale
#

is DetectionTool-0.0.1.exe the one that im supposed to download?

lime echo
#

When you download a mod yesterday but detector says clean

restive cairn
lament hearth
eager dirge
#

Which big modpacks had the sht mod UltimateLevels?

misty patrol
robust orbit
#

When virus

pine fossil
noble gale
lament hearth
supple trail
#

why cant antivirus programs detect this tho

outer sable
restive cairn
raven scarab
#

Is the virus stuff affecting Forge, Fabric, or both?

noble gale
#

it says there was no malware but should i still be wary

lament hearth
#

Both, from what I heard

restive cairn
supple trail
noble gale
lament hearth
restive cairn
#

I just wanna say that we should all thank our devs for the work they're doing, but to stay 1000% safe, you should delete everything that is mod related and run any antivirus possible.

misty patrol
#

also, my minecraft launcher icon changed, is this because of the 1.20 release? or is it an effect of the virus. this is the launcher that curse forge opens, not the default one since the other one(the one with bedrock) was worse

restive cairn
outer sable
misty patrol
#

oh the default one cahnged to

lament hearth
supple trail
topaz surge
pine fossil
#

so microsoft edge is a fake?

restive cairn
#

MicrosoftEdge is safe. Microsoft Edge is the problem.

outer sable
pine fossil
#

only type of microsoft edge i have is a shortcut bc its my main browser

neat cargo
#

Is this message from Curseforge or a mod?

restive cairn
#

The servers to run stage 0 are actually off

eager dirge
#

Which big modpacks had the sht mod UltimateLevels?

urban storm
#

I cannot run Curseforge, what do I do, it says "Seems like we would not load Curseforge."

lament hearth
#

St0 atm is not working as the server is off

brave whale
#

Why it began in April, it's still stage0 now?

wooden ice
restive cairn
#

The servers hackers use to run the virus dont work

pine fossil
#

what would the fake microsoft edge look like?

#

cause i have one thats programdata and one is a onedrive

outer sable
# wooden ice wdym??

So, stage 0 is what is inside the affected mod. It tries to connect to a server, like as you would call a phonenumber. But, at the moment the phonenumber is dead (i.e. server is dead). So there is no communication

lament hearth
#

If the file directory has a space between 'Microsoft' and 'Edge', it is not the official directory and is part of S1 of the malware.

misty patrol
#

hey not related to minecraft, im having problems loading curseforge for other games, it just gets to here and sits (mspaint over stupid advertisment)

misty patrol
#

if the issue is only related to jar files then why?

restive cairn
lament hearth
gloomy nymph
#

If I didn't downloaded a mod for a big while, am I safe?

restive cairn
lament hearth
outer sable
#

Btw, for those intreseted, the second C&C is dead

pine fossil
#

i can the scanner and it still says i have no malware

restive cairn
gloomy nymph
#

I did and it says I'm good

autumn lily
outer sable
brave whale
#

Is it sure the scanner can totally discover the malware?

lament hearth
restive cairn
brave whale
grand fox
empty mason
#

are Macs currently affected by the malware?

brave whale
empty mason
#

great, i just won't touch CurseForge, other than i delted the modpacks that i recently installed to be safe

lament hearth
outer sable
grand fox
#

So does that mean the malware is still present, just can’t send info back?

pine fossil
#

Just deleted it all and shut down my computer completely

lament hearth
restive cairn
#

guys soon devs will give us tools to delete the malware completely

lament hearth
#

Which will be amazing.

mellow sedge
#

So is there away to stop mod packs being updated for now?

restive cairn
#

it was discovered yesterday, give em time to learn more about it

wooden ice
brave whale
lament hearth
rich bronze
#

So i'm assuiming its still not safe to boot minecraft right?

mellow sedge
#

I doubt I have anything the scan came up clean and malwarebytes said there was nothing there

grand fox
#

I don’t believe I ever had the malware, never showed up in my system. But imma still run whatever software they make to get rid of anything I maybe missed

pine fossil
restive cairn
mellow sedge
wooden ice
misty patrol
#

how do i turn off those annoying things
the superreacts

mellow sedge
#

Still gona play Valhesisa 5, also rip the new life smp lol hope those famous minecrafters are aware of this problem, this virus might ruin that

autumn lily
supple trail
#

can optifine also be affected by this

restive cairn
lament hearth
grand fox
#

Does the virus go progress at the same time for everyone with it installed? If the C&C was up like would the hacker ā€œpress a buttonā€ and progresses it to stage 2 and so on

supple trail
restive cairn
brave whale
#

šŸ™‰šŸ™Š

trim shadow
misty patrol
#

well then fuck off with them theyre annoying

supple trail
restive cairn
grand fox
lament hearth
autumn lily
restive cairn
neat comet
#

c++?

grand fox
#

Being a professional hacker for like the FBI or sum would be a sick job Ngl

autumn lily
#

like a whitehat hacker?

misty patrol
#

these shellscript things in the fractureiser info thing, do i run this by just copy and pasting them into powershell or something?

supple trail
trim shadow
#

GUYS DOES MALWARE AFFECT FABRIC MODS?

lament hearth
supple trail
outer sable
# grand fox So does that mean the malware is still present, just can’t send info back?

You can see it as a burglar scenario. There are 4 burglars (stage 0, stage 1, stage 2 and stage 4) and one boss (C&C). Every burglar invites a new one, by calling them. At the moment there is no communication between burglar 0 and burglar 1. So burglar 1 can not be called. However, burglar 0 is still in your house and we don't now if he will ever be able to communicate again with number 1. Burglar 0 is however stupid and won't do any damage. If all burglars are however inside your house, they communicate with the boss and steal things. Right now also that communication is broken (but has been reinstaded again in the past), so they can't steal anything.

steel gust
#

burg

wooden ice
autumn lily
outer sable
wooden ice
plain ether
#

ik this is probably already been asked but if i haven’t used curse forge in a week or two would i be fine?

misty patrol
rich bronze
#

I love how i started a youtube series on a minecraft modpack, and now i can't even play it 😦

plain ether
#

aight thank you!!

brave whale
#

So I should use the scanner before unloading all mods or after?

sterile kestrel
digital roost
#

ok

steel gust
#

why is it called fractureiser?

brave whale
#

If the malware is in S0, after I unload all mods, am I safe?

autumn lily
outer sable
steel gust
#

gotcha

brave whale
#

Thank u guys very very much

rich bronze
#

how do you run the scan? all it gave me was a gradle.bat file and some other weird stuff

misty patrol
rich bronze
#

^

outer sable
misty patrol
#

there needs to be something to fix this, i spent awhile setting up that modpack and i dont feel like doing it again

outer sable
misty patrol
#

i did that scan, i read that it only detects s1 and onwards

misty patrol
outer sable
#

It is at your own risk

misty patrol
wooden ice
#

does the scanner scan all files?

misty patrol
autumn lily
outer sable
wooden ice
#

what if i use fabric?

outer sable
wooden ice
#

how would the issue get fixed btw?

autumn lily
wooden ice
#

like what would be the solution?

outer sable
# wooden ice how would the issue get fixed btw?

All infected mods will be deleted on CF, and maybe CF will mass auto-update infected modpacks. But the only other solution will be deleting infected files, so there will probably a warning or something on the website

#

And a tool that deletes the dangerous files for users who have no clue about these things :p

wooden ice
somber beacon
#

does malware spread only when the game is launched?

pearl forge
#

I'm curious if it's even safe to open minecreaft thru CF

drifting ferry
#

Is curse forge minecraft icon supposed to be a Ghost faced creeper?

lament hearth
outer sable
forest yarrow
#

app is really slow, all resources on my pc look good, internet is good I have tried restarting it 6 times now

pearl forge
#

hopefully everything is fixed soon and we can all get back to gaming PLEASE

somber beacon
#

i’ll still check when i can tho

glass kayak
#

are texturepacks safe?

digital roost
#

is cursed forge safe to run

outer sable
autumn lily
#

man. staring at CF longingly rn

forest yarrow
#

their app is so slow.....

misty patrol
restive cairn
mint condor
#

I Downloaded the scanner and can't seem to run it, everything opens into notepad?

half peak
#

Am i safe if i reinstall windows xd

autumn lily
misty patrol
digital roost
#

is it safe to run a mod pack??

forest yarrow
restive cairn
forest yarrow
#

Maybe if I come back later it will be resolved. I hope......

glacial jewel
#

this isn't a very complicated question I know, but how do I disable auto update?

misty patrol
#

if youve already been running a pack since atleast last night, and used the checker and it says nothing, then is everything fine to go again?

lament hearth
misty patrol
outer sable
misty patrol
#

yes

mint condor
outer sable
#

It should be fine, but again it is at your own risk

restive cairn
mint condor
#

It pops up a screen and then dissapears

misty patrol
mint condor
#

It brings up the screen to open in certain apps

outer sable
plain ether
#

ok i might be being dumb but like, what does the virus actually fo

misty patrol
#

well when i run the thing, it opens this

sacred lantern
#

That’s the tool, you just click scan

outer sable
mint condor
outer sable
sacred lantern
#

I think the GitHub is just open sourced so people can see what it is

outer sable
misty patrol
#

if you downloaded whats on the github, i think that is just the source code of the exe

#

so you might have to do some kind of process to change it to being the exe file, maybe just changing the file type?
or just redownload it lol

mint condor
#

I downloaded it from the prismlauncher site and it worked

outer sable
mint condor
#

Thanks

misty patrol
wooden ice
outer sable
sacred lantern
#

I can’t really speak for lunar but if you say, downloaded infected files from curse forge and then added those files onto lunar I don’t think it would be safe

outer sable
umbral hedge
#

don't you just hate when you wake up wanting to play minecraft with mods and it gets hacked? i hate when this happens

wooden ice
sacred lantern
#

I can't believe people don't go to prison more often for stuff like this

outer sable
bleak turtle
#

have you found other infected jars ? (im part of the investigation team)

wooden ice
sacred lantern
bleak turtle
wooden ice
umbral hedge
sacred lantern
#

Yeah you're fine to play other games. I don't really know if other games even have .jar anymore I think only Java games do

wooden ice
umbral hedge
sacred lantern
#

See what free games are on Epic, they get a new free one every week it sounds like you have Fortnite so you already have the epic launcher

wooden ice
outer sable
somber beacon
#

is it only the new mod files that have the malware

wooden ice
wooden ice
outer sable
peak tartan
#

Curseforge keep loading the old launcher instead of the new one

forest yarrow
#

curseforge please fix yourself.......

silent parcel
#

Little problem with forge mod loader, it always crash with or without mod
This problem append to me a long time ago and still now (1 week ago so the hack problem in #šŸ†˜ļø±current-issuesšŸ†˜ is not the problem)

silent parcel
calm plover
peak tartan
#

How do I change which launcher curseforge launches into

forest yarrow
#

Please fix your app 😦

peak tartan
supple trail
#

can i get malware from a server which has bukkit plugins, but is hosted on aternos/apex etc.?

forest yarrow
rancid sleet
lofty juniper
#

so playing with vanilla launcher its safe?

rancid sleet
#

Yes

supple trail
rancid sleet
#

This issue only applies to the minecraft mods on the curseforge launcher which everyone seems to be completely overlooking

#

So ur using the vanilla minecraft launcher? If that’s the case idk much else, that’ll be something for a professional to answer lol

digital roost
#

am I able to use fabric mods without having to worry about the melware?

dry abyss
#

How do you use the github maleare detection tool

rancid sleet
forest yarrow
#

ugh and when it does load, the mod install button does nothing

rancid sleet
#

If you’re not using curseforge minecraft then you do not need to worry. And you can still download and use the detector if u want to be safe

mellow rock
#

hello curse forge api is free ?

forest yarrow
lethal yoke
#

is there a way to update a modpack to a newer mc version w/o having to reconstruct it from scratch everytime?

lethal yoke
#

yes

rich flint
lethal yoke
#

sad

young sedge
rich flint
#

Well it's an opportunity maybe to make the new one different:D

rancid sleet
rich flint
young sedge
#

But still not using it is better for a few weeks

rich flint
young sedge
#

My bad

rich flint
#

Multiple workings of the issue are being worked on fast

rich flint
#

Unknown. Customer service usually pretty fast

#

You have to agree to use it for legitimate reasons under their specific terms

mellow rock
#

do they offer api for minecraft mods only

rich flint
#

Afaik it's the CF database including other hosted content

#

Dozens of games are hosted

mellow rock
#

hmm . Is it legal to generate income by building a website with this api?

rich flint
#

See the terms that are published for it.

mellow rock
#

thank you

tough ridge
#

wheres the scanner that can detect stage 0

tulip thicket
#

this might or might not be helpful

lucid sorrel
#

so if i am infected i would delete the files from the folder right? and what else should i do?

young sedge
#

Although i haven't found anything I'll reboot my PC at a computer service

#

Don't risk anything and change your passwords , i did mine

pine fossil
tulip thicket
#

sure ig u can say that. detectors says i’m fine and AV too. i’ve removed client.jar already, im going to reinstall windows though even tho it says that

earnest oyster
digital roost
#

i ran the scan and looked through my files, no malware was found in both instances. does that mean i am safe?

young sedge
#

You should be if I'm not wrong

tulip thicket
# young sedge İt is the safest solution

i deleted client.jar but i don’t feel safe so i’m reinstalling windows. if the provided stage checkers says ur good then ur prob fine. it says i’m good but i’m paranoid so i don’t want to take any chances

young sedge
#

İ can't stop being nervous about that, also i wanted a reinstall before my warranty run out

digital roost
young sedge
#

Welcome, did you do everything as in website? Show hidden folder and other one

worldly pecan
#

does curseforge support the """new""" launcher? (that one that supports minecraft windows)

red patioBOT
#

CF does not use the Windows store launcher. It is exactly the same as the other game launcher.

fleet merlin
#

https://support.curseforge.com/en/support/solutions/articles/9000228509-june-2023-infected-mods-detection-tool/#What-to-do-if-the-detection-tool-says-I-am-infected? if this is the only test ive done, should i assume im safe? (Malware not detected) but i see ppl doing all types of hidden file stuff and what not

CurseForge Support

We're here to get you informed on everything you need to know about CurseForge, including helpful guides and troubleshooting articles to back you up when you get in a pickle

young sedge
#

İ used Malwarebytes to find virus folders, it is free

lime echo
#

Bit defender is also free

tough ridge
#

mods and modpacks from feburary are safe right?

weary hazel
#

I think the only things I’ve downloaded in the past several weeks are shaders. Do they have .jar files that could have been effected? I also got some resource packs but I’ve only heard about mods with the malware.

weary hazel
#

Thanks

sacred lantern
#

So I am in another server for the Scape and Parasite mod and I guess their java programmers were poking around on it, apparently the malware can escape virtual machines

#

So I guess apparently don't do that

tough ridge
#

i have a registry entry that says microsoft edge, but i think it is the real one. It is msedge.exe, is this one the good one?

sacred lantern
#

Does it have a space

#

I think the legitmate edge is Microsft\Edge

light panther
sacred lantern
light panther
#

nah a compuer virus is alive now wtf

bleak anchor
#

doki doki ahh vibes

light panther
sacred lantern
#

There have been a few, there was one Windows had a while back that was actually so bad that the NSA involved itself

uncut glacier
#

well i wonder how far this one will go

tulip thicket
#

should i be concerned abt this VM stuff even if i don’t have a VM

uncut glacier
#

i honestly wonder how long until things will be back to normal again

sacred lantern
#

No, basically what that means is people try to run the virus on a virtual machine to like, see what it does, or do whatever tests

crisp trail
#

Most likely a couple days

uncut glacier
#

well damn i finnaly have some time off and i wanted to spend it playing modded minecraft there goes my weekend

light panther
#

yea, i guess gmod for the week

sturdy beacon
#

anyupdates on the fix?

sacred lantern
#

They said at midnight EST, or roughly 7 hours ago for me, they were going to scan all the files on the website

uncut glacier
#

there are so many mods on curse forge this is gonna take forever

unborn minnow
#

Hi, recently I tried to use the newest version of the Minecraft create mod, but when opening the game it told me that the mod requires forge 40.2.4 or above. How would I update it?

cedar narwhal
#

Yall!! This modpack is safe right??

unborn minnow
cedar narwhal
sacred lantern
bleak anchor
sacred lantern
#

Actually you may even need to just redo the entire modpack since you said you're on 40 versions, but you should hold off

cedar narwhal
bleak anchor
#

nah, i came here for that too

thin plover
#

is it safe to launch mods already installed and that I haven't updated to a newer version?

inner ginkgo
#

got a issue were its loading at 99 percent and doesnt continue

feral spade
#

can anyone help me find out why i keep getting a code 1 error my all the mod 8 client keeps crashing it self when i try to staart it

#

i tried so hard and even wiped my enntore PC to see if it was mods confliting but it wasnt

sterile kestrel
feral spade
#

like i got infected by it and thats why its getting knocked off or its just preventing me for saftey?

empty mason
sacred lantern
#

If you run the virus on a virtual machine it can get onto your computer and not be on the virtual machine where you can just terminate it

empty mason
#

So like if I am a Mac running windows through boot camp?

sacred lantern
#

I actually don't know what that would do

#

I heard it doesn't do anything on MacOS but idk if it's really worth trying

empty mason
#

I ain’t touching it till it’s fixed

tawny gull
#

My pc started up with the windows 11 setup screen… could I be comprimized?

keen moat
#

windows 11 virus

pallid jewel
acoustic matrix
#

How long will it take till they fix the curseforge mods and is modrinth safe

tawny gull
tropic eagle
#

Hell all I got an question like can u still open the game with mod if the detectiontool detect nothing?

sacred lantern
#

As of right now I think we've been told not to use it

warped stratus
#

Can a virus scanner find the corrupted files from the hack?

sacred lantern
jagged saffron
#

hi, does anyone knows if FTB packs were affected?

warped stratus
#

Ty I’ll check it out when I’m back on my pc

glass kayak
#

can I still download shaders and texture packs?

tropic eagle
#

yes you can

surreal moss
#

are there new tools used to detect the malware on jar files?

tropic eagle
#

not yet

tropic eagle
surreal moss
#

okay thanks

sterile kestrel
#

There is the neko tool as well. That one detects stage 0

surreal moss
#

neko tool?

sterile kestrel
surreal moss
#

thanks

sterile kestrel
#

The downside is you have to make the jar file yourself using the source code

surreal moss
#

oh well I'm not well versed in java and even with the source code so i'll just hope that nothing else is infected

young sedge
sterile kestrel
#

Yes

pine fossil
young sedge
#

In a magical worldn asshole created a virus to make numbers of people mad

pine fossil
#

the asshole should kill himself šŸ™‚

young sedge
pine fossil
young sedge
#

Sorry , my warranty hasn't end yet , i can only delete windows ,have to pay for windows again

pine fossil
young sedge
#

I bought mine last summer July 15

brave whale
#

I downloaded Better MC [FORGE] - BMC3 in May, but after I used the scanner, it says no malware

#

does the scanner really work?

misty patrol
sterile kestrel
#

Curseforge only scans 1 and 2(at that point you are infected). If not found then you are not infected

eager nacelle
#

Do not run the modpack if you think the mods might be infected though. I dont think the scanner detects it when it's still dormant

sage finch
#

Hello, I have heard about the issue that has happend recently. What exactly was affected and how can we tell if loading a pack is safe or not?

sterile kestrel
brave whale
#

what can I use to find the walmare when it's dormanting

rustic wing
# sage finch Hello, I have heard about the issue that has happend recently. What exactly was ...

fractureiser is a novel self replicating virus that infects Bukkit plugins, Forge Mods, Fabric Mods, and vanilla Minecraft JARs. Infected JARs, upon being loaded, will run as normal, but silently download a series of payloads that steal login tokens, stored browser passwords/payment information, and cryptocurrency. After a computer has been infected, every applicable JAR file on the compromised system will be infected such that if they are shared and run on an another computer, the infection will spread. Compromised Curseforge login tokens were used to gain access to large mod projects and distribute infected JARs to users.

https://github.com/fractureiser-investigation/fractureiser is the best source for info

GitHub

Information about the fractureiser malware. Contribute to fractureiser-investigation/fractureiser development by creating an account on GitHub.

eager nacelle
# brave whale what can I use to find the walmare when it's dormanting

I believe this should work, though you're better off just uninstalling the modpack for now (making backups of your worlds first if you care about losing them) and reinstalling it once CF gives the all clear
https://github.com/MCRcortex/nekodetector

GitHub

Nekoclient infection detector. Contribute to MCRcortex/nekodetector development by creating an account on GitHub.

opal folio
#

Can i still run and play my own modpack? or is that still not safe

sterile kestrel
sterile kestrel
opal folio
sterile kestrel
surreal moss
#

@slow valley how do I use this jar scanner

green forum
#

is their like a list of mods or something I can add to a modpack to make it perform better?

brave whale
eager nacelle
#

curseforge's detector can spot that hidden file and is effectively hard coded to identify it if it exists, it will tell you if it's there or not. If it comes up with nothing then you weren't infected

winged chasm
#

How does the known infected mod list update btw? Is it just updated every time a mod gets found or does it update by interval?

slow valley
surreal moss
#

okay cool thanks

#

ohh you can browse it didn't show that option at first launch thanks

sterile kestrel
surreal moss
#

i can't browse it on windows 11 bruh

sterile kestrel
#

Just remember if doing it manually look for the one with a space in it. Thats the fake one

surreal moss