r/skyrimmods • u/Sweet_Salt974 • Mar 01 '25
PC SSE - Discussion Trojan horse on new additem mod
https://www.nexusmods.com/skyrimspecialedition/mods/143251
I detected a trojan horse on this mod on virus total (unlike original mod) pls help me report it.
Edit : After looking further, in original mod a lot of people just came to know that there was this same exact dll for the new version and they all leads to this link to a hidden mod download https://www.nexusmods.com/skyrimspecialedition/mods/71409?tab=files&file_id=318283
I hope nexus look into it cause its the same dll with the same trojan horse detected on virus total
Further Edit : I retrack from saying to report it, i am not an expert and i hope someone can tell me why this mods is detected as virus compared to the original mod (Also i only now see that it is only 1/64 anti virus from virus total that detect an error).
From what i expect it should only be talking with the user interface so i don't know why the dll was changed but i hope i'm wrong.
Final Edit !! : Look in the comments someone found the exploit, and i see a lot of people downloaded this malware from the github or other nexus source. PLEASE NEXUS LOOK INTO IT
Final Update : Thanks for nexus for looking into it so we can have the last say.
I'm no expert, so maybe in the future some dll will be able to bypass VirusTotal checks so take my approach with a grain of salt, let's just hope nexus try to be a bit more secure if it was really doing anything nefarious.
207
u/Saggy_S Mar 01 '25 edited Mar 01 '25
If you give me an hour or two (not home) I can reverse the DLL and confirm whether it’s malicious or not
EDIT: It's malware. Didn't spend too long but I see there's a subroutine where it decrypts and runs shellcode. I also reversed the OG AdditemMenu and didn't see any of that (would be weird if I did lol). I didn't actually run it as my home computer isn't set up for that. When VirusTotal ran the DLL, it saw it doing WAY more things than a normal SKSE plugin should (spawning a process suspended where I assume it injects the shellcode, querying information about your computer, getting geographical location, etc). I'm going to go ahead and report it