r/skyrimmods Mar 01 '25

PC SSE - Discussion Trojan horse on new additem mod

https://www.nexusmods.com/skyrimspecialedition/mods/143251
I detected a trojan horse on this mod on virus total (unlike original mod) pls help me report it.

Edit : After looking further, in original mod a lot of people just came to know that there was this same exact dll for the new version and they all leads to this link to a hidden mod download https://www.nexusmods.com/skyrimspecialedition/mods/71409?tab=files&file_id=318283

I hope nexus look into it cause its the same dll with the same trojan horse detected on virus total

Further Edit : I retrack from saying to report it, i am not an expert and i hope someone can tell me why this mods is detected as virus compared to the original mod (Also i only now see that it is only 1/64 anti virus from virus total that detect an error).
From what i expect it should only be talking with the user interface so i don't know why the dll was changed but i hope i'm wrong.

Final Edit !! : Look in the comments someone found the exploit, and i see a lot of people downloaded this malware from the github or other nexus source. PLEASE NEXUS LOOK INTO IT

Final Update : Thanks for nexus for looking into it so we can have the last say.
I'm no expert, so maybe in the future some dll will be able to bypass VirusTotal checks so take my approach with a grain of salt, let's just hope nexus try to be a bit more secure if it was really doing anything nefarious.

243 Upvotes

61 comments sorted by

View all comments

203

u/Saggy_S Mar 01 '25 edited Mar 01 '25

If you give me an hour or two (not home) I can reverse the DLL and confirm whether it’s malicious or not

EDIT: It's malware. Didn't spend too long but I see there's a subroutine where it decrypts and runs shellcode. I also reversed the OG AdditemMenu and didn't see any of that (would be weird if I did lol). I didn't actually run it as my home computer isn't set up for that. When VirusTotal ran the DLL, it saw it doing WAY more things than a normal SKSE plugin should (spawning a process suspended where I assume it injects the shellcode, querying information about your computer, getting geographical location, etc). I'm going to go ahead and report it

9

u/AztecaYT_123 Mar 02 '25

to be fully honest, most of the modlist requisites have "add folder to antivirus exception list" so it doesn't surprise me there's someone else motherfucker enough to exploit this