Project Zomboid bans rogue mods deploying "malicious code" to players' PCs

0
25

Project Zomboid bans rogue mods deploying "malicious code" to players' PCs

Project Zomboid developer The Indie Stone has confirmed that it has identified and taken action against a series of mods for the zombie game that were "creating malicious files outside of the Project Zomboid directory." The mods in question were add-ons for the popular 'True Moozic' soundtrack expander and were unrelated to its original creator. They have been removed from the Steam Workshop and the perpetrator has been banned, but The Indie Stone encourages anyone who thinks they might have been affected to take action.

The best Project Zomboid mods have long been a highly recommended way to customize and enhance your adventure. With the overhaul to Build 42, there are countless options to tweak the world of Project Zomboid to your liking, whether you're looking to dramatically raise the car count, add water pipes and plumbing, or build custom bandits that have specific talents to impede your progress. Among those is True Moozic, which includes support to add custom soundtracks.

The Indie Stone notes that it recently "received reports from multiple users regarding a mod that was allegedly generating malicious code when run." It then "immediately investigated the mod in question, which contained heavily obfuscated code, and confirmed that it was creating malicious files outside of the Project Zomboid directory." Upon digging a little further, the developer spotted a total of 14 mods from the same user, all containing the exploit. It estimates the total installs across them all at "between 500 and 2,200 devices."

Project Zomboid Build 42 mods exploit patched - A group of survivors work on renovating a house.

The user responsible has now been banned, and all affected mods have been removed, but The Indie Stone warns, "At this time, the full scope and behavior of the malicious files have not been fully determined. Because these mods were capable of creating files outside the game directory, we strongly recommend that anyone who downloaded them take appropriate security measures to ensure their system is safe. Simply uninstalling the mods is not sufficient."

The mods in question included soundtracks from a number of other games, including Risk of Rain, Persona 5, Nier: Automata, Roblox, and Minecraft. The Indie Stone notes that the exploit "only affected Build 42 branches." However, it did release a Build 41 security update yesterday, addressing "a separate vulnerability identified during an internal audit." It states, "At this time, we have found no evidence that this separate vulnerability has been exploited."

YouTube Thumbnail

The developer also clarifies that the malicious uploads "are not the True Moozic mod, nor were they created by the author of the True Moozic mod. The affected mods were simply add-ons - they did not leverage the True Moozic mod as part of the exploit, and they were made without the consent of the True Moozic mod's author." As all of the problem files have been removed, any mods still on the workshop are "not part of this incident."

In order to ensure that it doesn't leave the vulnerability accessible in any way, The Indie Stone has also updated its 'outdated unstable' branch to match the 'unstable' branch. This means that the outdated version "will continue to lag one content update behind unstable" for the foreseeable future.

Rechercher
Catégories
Lire la suite
Jeux
NetEase denies claims made by Suda51 that it's shut down an entire generative AI division
NetEase denies claims made by Suda51 that it's shut down an entire generative AI division...
Par Test Blogger6 2026-02-04 15:00:21 0 1KB
Technology
Get more reading done with 20% off the like new Kindle Paperwhite
Best Kindle deal: Get 20% off the like new Kindle Paperwhite...
Par Test Blogger7 2026-02-13 17:00:20 0 1KB
Jeux
Terraria teases "very exciting potential" for builders after celebrating one of its "largest player spikes" yet
Terraria teases "very exciting potential" for builders after celebrating one of its "largest...
Par Test Blogger6 2026-02-26 20:00:15 0 712
Technology
Get $600 off the Bluetti Elite 400 portable power station and stay prepared for emergencies
Best power station deal: Get $600 off the Bluetti Elite 400 portable power station...
Par Test Blogger7 2026-02-04 18:00:26 0 1KB
Jeux
This modder just added drivable cars to CS2, and it works shockingly well
This modder just added drivable cars to CS2, and it works shockingly well Move aside,...
Par Test Blogger6 2026-03-31 15:00:28 0 182