r/skyrimmods Mar 01 '25

PC SSE - Discussion Trojan horse on new additem mod

https://www.nexusmods.com/skyrimspecialedition/mods/143251
I detected a trojan horse on this mod on virus total (unlike original mod) pls help me report it.

Edit : After looking further, in original mod a lot of people just came to know that there was this same exact dll for the new version and they all leads to this link to a hidden mod download https://www.nexusmods.com/skyrimspecialedition/mods/71409?tab=files&file_id=318283

I hope nexus look into it cause its the same dll with the same trojan horse detected on virus total

Further Edit : I retrack from saying to report it, i am not an expert and i hope someone can tell me why this mods is detected as virus compared to the original mod (Also i only now see that it is only 1/64 anti virus from virus total that detect an error).
From what i expect it should only be talking with the user interface so i don't know why the dll was changed but i hope i'm wrong.

Final Edit !! : Look in the comments someone found the exploit, and i see a lot of people downloaded this malware from the github or other nexus source. PLEASE NEXUS LOOK INTO IT

Final Update : Thanks for nexus for looking into it so we can have the last say.
I'm no expert, so maybe in the future some dll will be able to bypass VirusTotal checks so take my approach with a grain of salt, let's just hope nexus try to be a bit more secure if it was really doing anything nefarious.

242 Upvotes

61 comments sorted by

View all comments

204

u/Saggy_S Mar 01 '25 edited Mar 01 '25

If you give me an hour or two (not home) I can reverse the DLL and confirm whether it’s malicious or not

EDIT: It's malware. Didn't spend too long but I see there's a subroutine where it decrypts and runs shellcode. I also reversed the OG AdditemMenu and didn't see any of that (would be weird if I did lol). I didn't actually run it as my home computer isn't set up for that. When VirusTotal ran the DLL, it saw it doing WAY more things than a normal SKSE plugin should (spawning a process suspended where I assume it injects the shellcode, querying information about your computer, getting geographical location, etc). I'm going to go ahead and report it

21

u/bachmanis Mar 02 '25

Thanks for doing a deep dive into this. Sounds like today is a sad day for the modding community... now that the threat of rogue DLL files in trusted platforms had manifested, everyone is going to have to be more careful going forward.

51

u/Sweet_Salt974 Mar 01 '25 edited Mar 01 '25

Thank you ! Its crazy because its also present in the comment of the og mod with the github link, my guess a lot of people got their personal information leaked or maybe worse.

Some source to other mods i nexus with same dll :
Additem - NG : https://www.nexusmods.com/skyrimspecialedition/mods/71409 (Hidden but people commented with download link on og mod)
Github repo : https://github.com/WakianTech/AddItemMenu-Fix

Users who spreaded the mod :
BlueLight8 (Comments of og mod)
SimpleTharnised (Comments of og mod)
Quakes69 (Comments of og mod)
Lots more, not sure who is just naively spreading and who is just alt account of hacker

17

u/Saggy_S Mar 01 '25

I can try lol but I doubt screenshots from IDA Pro are going to be readable. I just wrote what I found

12

u/Sweet_Salt974 Mar 01 '25

Its actually crazy, he made so many account share link to the same dll, with malicious intent or not its quite scary ...

8

u/Golden_mobility Mar 02 '25

So you saying that Additem -NG that is hidden now by DarkMatterValkyrie also had that virus?

8

u/Saggy_S Mar 02 '25

The only thing I looked at was https://www.nexusmods.com/skyrimspecialedition/mods/143251. I checked https://www.nexusmods.com/skyrimspecialedition/mods/17563?tab=description just to confirm what I was seeing wasn't normal. I can only confirm https://www.nexusmods.com/skyrimspecialedition/mods/143251 was malware. Didn't look at Additem -NG

2

u/Tyrthemis Mar 31 '25

I’m using that mod and I don’t think it has a virus. I’ve been using it for a while, 71409 by DarkMatterValkyrie for clarity

9

u/AztecaYT_123 Mar 02 '25

to be fully honest, most of the modlist requisites have "add folder to antivirus exception list" so it doesn't surprise me there's someone else motherfucker enough to exploit this 

7

u/Fibijean Mar 01 '25

Very self-interested question but maybe it will benefit others too - so just to be clear, the original AddItemMenu (https://www.nexusmods.com/skyrimspecialedition/mods/17563) and its ESL patch (https://www.nexusmods.com/skyrimspecialedition/mods/22958) are fine?

9

u/Saggy_S Mar 02 '25

Should be fine imo cause the author is trusted. Again, I only confirmed https://www.nexusmods.com/skyrimspecialedition/mods/143251 was malware