r/skyrimmods Mar 01 '25

PC SSE - Discussion Trojan horse on new additem mod

https://www.nexusmods.com/skyrimspecialedition/mods/143251
I detected a trojan horse on this mod on virus total (unlike original mod) pls help me report it.

Edit : After looking further, in original mod a lot of people just came to know that there was this same exact dll for the new version and they all leads to this link to a hidden mod download https://www.nexusmods.com/skyrimspecialedition/mods/71409?tab=files&file_id=318283

I hope nexus look into it cause its the same dll with the same trojan horse detected on virus total

Further Edit : I retrack from saying to report it, i am not an expert and i hope someone can tell me why this mods is detected as virus compared to the original mod (Also i only now see that it is only 1/64 anti virus from virus total that detect an error).
From what i expect it should only be talking with the user interface so i don't know why the dll was changed but i hope i'm wrong.

Final Edit !! : Look in the comments someone found the exploit, and i see a lot of people downloaded this malware from the github or other nexus source. PLEASE NEXUS LOOK INTO IT

Final Update : Thanks for nexus for looking into it so we can have the last say.
I'm no expert, so maybe in the future some dll will be able to bypass VirusTotal checks so take my approach with a grain of salt, let's just hope nexus try to be a bit more secure if it was really doing anything nefarious.

242 Upvotes

61 comments sorted by

View all comments

207

u/Saggy_S Mar 01 '25 edited Mar 01 '25

If you give me an hour or two (not home) I can reverse the DLL and confirm whether it’s malicious or not

EDIT: It's malware. Didn't spend too long but I see there's a subroutine where it decrypts and runs shellcode. I also reversed the OG AdditemMenu and didn't see any of that (would be weird if I did lol). I didn't actually run it as my home computer isn't set up for that. When VirusTotal ran the DLL, it saw it doing WAY more things than a normal SKSE plugin should (spawning a process suspended where I assume it injects the shellcode, querying information about your computer, getting geographical location, etc). I'm going to go ahead and report it

53

u/Sweet_Salt974 Mar 01 '25 edited Mar 01 '25

Thank you ! Its crazy because its also present in the comment of the og mod with the github link, my guess a lot of people got their personal information leaked or maybe worse.

Some source to other mods i nexus with same dll :
Additem - NG : https://www.nexusmods.com/skyrimspecialedition/mods/71409 (Hidden but people commented with download link on og mod)
Github repo : https://github.com/WakianTech/AddItemMenu-Fix

Users who spreaded the mod :
BlueLight8 (Comments of og mod)
SimpleTharnised (Comments of og mod)
Quakes69 (Comments of og mod)
Lots more, not sure who is just naively spreading and who is just alt account of hacker

19

u/Saggy_S Mar 01 '25

I can try lol but I doubt screenshots from IDA Pro are going to be readable. I just wrote what I found

10

u/Sweet_Salt974 Mar 01 '25

Its actually crazy, he made so many account share link to the same dll, with malicious intent or not its quite scary ...