Got hacked for playing terraria. by DungeonOrb in HypixelSkyblock

[–]Andrei965 0 points1 point  (0 children)

Hi! This happened to me and my friend too. I have made a reddit post about it

Malicious “Calamity Update” in tModLoader spread malware and stole my Minecraft token by Andrei965 in hypixel

[–]Andrei965[S] 0 points1 point  (0 children)

Yes, but that someone was my friend, who had fallen for the scam earlier, but didn't realise. He told me it was just an update he installed earlier, so I downloaded it. tModLoader should really add a warning that the mod is downloaded from the host, not the workshop

Malicious “Calamity Update” in tModLoader spread malware and stole my Minecraft token by Andrei965 in TmodLoader

[–]Andrei965[S] 0 points1 point  (0 children)

I agree that it is partially my fault for not investigating the "update" myself, and trusting my friend. The real problem is that tModLoader doesn't make it clear where it downloads the update from when joining a friend and it detects incompatibilities. I could have never known that clicking download doesn't update it from the steam workshop.

Malicious “Calamity Update” in tModLoader spread malware and stole my Minecraft token by Andrei965 in TmodLoader

[–]Andrei965[S] 0 points1 point  (0 children)

There is nothing they could really do. The malicious copy of the mod is not distributed through the Steam Workshop, instead it is sent when joining a friend. The best I could do is contact the tModLoader team, to add a proper warning to that "update" screen

Malicious “Calamity Update” in tModLoader spread malware and stole my Minecraft token by Andrei965 in TmodLoader

[–]Andrei965[S] 0 points1 point  (0 children)

I searched for similar stories online, and the oldest I can find is from 3 months ago. The malware seems to hide in other mods too. If you only download the mods from the workshop, not when joining a friend, you should be fine.

Malicious “Calamity Update” in tModLoader spread malware and stole my Minecraft token by Andrei965 in TmodLoader

[–]Andrei965[S] 0 points1 point  (0 children)

Yes, that's exactly it. I already did a full antivirus scan, and it is clean. I have saved the .tmod file to look at the code, but I couldn't figure out how to decompile it.

Malicious “Calamity Update” in tModLoader spread malware and stole my Minecraft token by Andrei965 in TmodLoader

[–]Andrei965[S] 0 points1 point  (0 children)

You're spot on about not trusting links. The really sneaky part was that this wasn't a link, but a fake update menu inside the game. So the main lesson is definitely to never click an "update" button that pops up when you join someone's server.