your current location:首页 > news>Some CurseForge accounts are suspected to be stolen and uploaded with malicious procedures, please download resources ca

Some CurseForge accounts are suspected to be stolen and uploaded with malicious procedures, please download resources ca

2024-12-18 03:45:51|Myriagame |source:minecraft skins

According to the announcement issued by Iris Shader developer Hedge Hog, in recent hours, they found that dozens of accounts uploaded some modules/integration packages containing malicious programs.The affected game versions mainly include 1.16.5, 1.18.2 and 1.19.2.Many well -known modules/integration packages have also been affected.Based on the affected CurseForge account, it is likely that someone has waived two -step verification of CurseForge directly to their account to upload files.

If you have downloaded these affected modules or modules, please isolate the files immediately and kill the computer for the computer. In addition, please download the module/module bag from CurseForge in the near future, including using a promoter from CurseForge APIDownload the module function.

Taking the DungeonsX module as an example, after starting, it will automatically download a Java Class file from the Internet and load it into the game, execute a command to download the malicious program again, and save it as executable files.The module has been added to all Luna Pixel Studios's integration package and is archived by the attacker.It is foreseeable that these modules may appear again in the future and have been attacked by thousands of people.Fabulously Optimized integrated package is also affected by this incident. The newly uploaded integrated package of its account contains a FORGE module. Fortunately, the module has never been downloaded, so it has not caused harm.

Known integrated package/module:

When dungeons arise, Lunapixelstudios participated in maintenance projects such as Lunapixelstudios (when the dungeon emerges), Sky Villages (Sky Village).

Better MC Modpack series.

Self -check method: Delete the following files (if any)

For unix: ~/.config/.data/lib.jar

For Windows:%LOCAPPDATA%/Microsoft Edge/Libwebgl64.jar or ~/AppData/Local/Microsoft Edge/Libwebgl64.jar

According to the results of the counter -compilation, the malicious program will turn your computer into part of the zombie network and leave the back door on your computer.

The malicious program is mainly aimed at Linux users, such as server, etc.It is worth noting that Windows users may also be affected by this.

Infected module files downloaded from the Internet (counter -compilation): https://pastebin.com/k2zqkbez

Screenshot of the back door program code released by malicious program:

minecraft

Some sample files: https://wwif.lanzouw.com/ilost0yilvfa decompression password: this isusSafe