Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

More fake DSM's with malicious code in them! Please watch out! #121

Open
5vl opened this issue Jun 8, 2022 · 29 comments
Open

More fake DSM's with malicious code in them! Please watch out! #121

5vl opened this issue Jun 8, 2022 · 29 comments

Comments

@5vl
Copy link

5vl commented Jun 8, 2022

https://github.com/skyblocknerd13/Dankers-Skyblock-Mod is fake. I decompiled the jar, and it had an extra class!
image
This is probably some kind of token logger.
Please watch out with what you download!

@cursefroge
Copy link

yep, if you go to http://breadcat.cc its... something

@5vl
Copy link
Author

5vl commented Jun 24, 2022

yep, if you go to http://breadcat.cc its... something

Interesting site.. definitely as a cover-up

@cursefroge
Copy link

It also says "I make Minecraft stealers"

@3niXboi
Copy link

3niXboi commented Jun 29, 2022

Hi! I know of one case where this exact mod you referenced lead to stolen credentials and in game items gone. The user has many repositories, different skyblock mods, all open source, all copied, and I am guessing all containing this exact file. I am now going to check the rest of them and submit a detailed report on Github (perhaps it does something). I will also post the text of my report here once it's done, if you (@EnderC00kiez @5vl) and others reading this could report him (https://github.com/skyblocknerd13) just sending a reference to that post even, that would be a huge help!

@5vl
Copy link
Author

5vl commented Jun 29, 2022

@3niXboi I didn't look at his other repos, although I'd definitely expect it. Good luck on the report - GH will ban them for sure.

@3niXboi
Copy link

3niXboi commented Jun 29, 2022

I have completed the report, I will post it here in the next message. Please report him for malicious software and send this as a reference. I found traces of obfuscation in 2 of the repositories, one of them being the one you previously found (edited 11 days ago after you made this post). Could be he is watching this thread. Hopefully support gets him banned before he deletes his repos. By the way @5vl he had the same grabber in all of his 10 other repositories, with minor changes and quite pitiful attempts at obfuscation, if any.

@3niXboi
Copy link

3niXboi commented Jun 29, 2022

This user (skyblocknerd13) has multiple repositories containing only compiled files with copied code from other (legit) sources, that are genuine Minecraft mods. He then adds malicious code including a token grabber to get access to the user's Minecraft login credentials. He then uploads only the compiled executable files to his repository. These upon running give the attacker access to their Minecraft account, and I know about one case where this lead to them logging on and ruining a (Hypixel Skyblock) profile.

Here are a few examples:

  1. Danker's Skyblock Mod
    skyblocknerd13's repository (containing malicious code): https://github.com/skyblocknerd13/Dankers-Skyblock-Mod
    the original repository: https://github.com/bowser0000/SkyblockMod

A github user (@5vl) has decompiled the executable and found an extra class containing the token grabber and opened an issue on the original mod, to warn users: #121.
He has since committed to the repository and changed the file, in an attempt to most likely obfuscate the code. A very similar function still exists in a different file but it's hard to read. It is now in the LootTrackerUtils class.
image.png

  1. Skytils
    skyblocknerd13's repository (containing malicious code): https://github.com/skyblocknerd13/Skytils
    the original repository: https://github.com/Skytils/SkytilsMod

This repository still contains the malicious code in the same file as in the first mod (updater class).
image.png

  1. Scrollable Tooltips
    skyblocknerd13's repository (containing malicious code): https://github.com/skyblocknerd13/Scrollable-Tooltips
    the original repository: https://github.com/Sk1erLLC/ScrollableTooltips

This repository contains the malicious code in a different file (errors class)
image.png

  1. Not Enough Updates
    skyblocknerd13's repository (containing malicious code): https://github.com/skyblocknerd13/NotEnoughUpdates
    the original repository: https://github.com/Moulberry/NotEnoughUpdates

This repository still contains the malicious code in the same file as in the first mod (updater class).
image.png

  1. NotEnoughCoins
    skyblocknerd13's repository (containing malicious code): https://github.com/skyblocknerd13/AH-BIN-Sniper-Mod-
    the original repository: https://github.com/NotEnoughCoins/NotEnoughCoins

This repository contains the malicious code in a different file (errors class)
image.png

  1. SkyblockExtras (SBE)
    skyblocknerd13's repository (containing malicious code): https://github.com/skyblocknerd13/SBE-Skyblock-Extras

The original mod in this case is not open source. Therefore the 'mod' only contains the grabber.
image.png

  1. Patcher
    skyblocknerd13's repository (containing malicious code): https://github.com/skyblocknerd13/Patcher
    the original repository: https://github.com/Sk1erLLC/Patcher

This repository still contains the malicious code in the same file as in the first mod (updater class).
image.png

  1. Skyblock Addons (SBA)
    skyblocknerd13's repository (containing malicious code): https://github.com/skyblocknerd13/SkyBlockAddons
    the original repository: https://github.com/BiscuitDevelopment/SkyblockAddons

This repository contains the malicious code in a different file (errors class)
image.png

  1. Dungeons Guide
    skyblocknerd13's repository (containing malicious code): https://github.com/skyblocknerd13/Skyblock-Dungeons-Guide
    the original repository: https://github.com/Dungeons-Guide/Skyblock-Dungeons-Guide

This repository still contains the malicious code in the same file as in the first mod (updater class).
image.png

  1. Hypixel Dupe Mod
    skyblocknerd13's repository (containing malicious code): https://github.com/skyblocknerd13/Hypixel-Skyblock-Dupe-Mod/blob/main/Skyblock-Dupe-Mod-1.2.jar

In this case there is no original mod, the whole code is just the same grabber.
image.png

@cursefroge
Copy link

Sent a report! Waiting for GH to reply/take action.

@3niXboi
Copy link

3niXboi commented Jun 29, 2022

@EnderC00kiez Thank you! The URL the data was sent to is operated by Cloudflare, meaning we don't know much about who does this other than his province and country. I won't share that here tho, as it might conflict with the community guidelines. Judging by the repository I think a few people have been targeted by this other than this one instance I know of. Hopefully he gets banned and it doesn't happen again!

edit: The first search result on bing if you type in "Dankers skyblock mod" is the malicious one. Hope he gets banned soon!

@cursefroge
Copy link

I'm going to report breadcat's website to cloudflare, to hopefully stop the connections for a while, then if we can unmask anything, we can proceed from there.

@5vl
Copy link
Author

5vl commented Jun 30, 2022

Thank you for all this info @3niXboi - I'll also report him to GitHub now, and the website to cloudflare and whatever other company/companies is/are involved.

@5vl
Copy link
Author

5vl commented Jun 30, 2022

Reported to GitHub & cloudflare, both linking to your comment!

@5vl
Copy link
Author

5vl commented Jun 30, 2022

I also found (what I think is) their hosting! In nr 4 (NEU) you can see "egirlpartey.ddns.net", which when I ping it returns an IP of a hosting provider. They also have a nice abuse email address! I'll make sure to send them an email as well.

Edit:
image

@5vl
Copy link
Author

5vl commented Jun 30, 2022

@3niXboi @EnderC00kiez - User is now removed from GitHub!

image

@cursefroge
Copy link

cursefroge commented Jun 30, 2022 via email

@3niXboi
Copy link

3niXboi commented Jun 30, 2022

@EnderC00kiez @5vl Thank you so much for everything!

@cursefroge
Copy link

hmm... new closed-source github repo with the same name, link: https://github.com/Sk1erLC/Dankers-Skyblock-Mod

@5vl
Copy link
Author

5vl commented Jul 18, 2022

@EnderC00kiez Yikes - I'll make sure to report it as well

@5vl
Copy link
Author

5vl commented Aug 8, 2022

@EnderC00kiez Sigh, some more to report I guess...

@bowser0000 bowser0000 pinned this issue Aug 10, 2022
@cursefroge
Copy link

cursefroge commented Aug 10, 2022

it seems like a bot posting multiple skyblock mods with malicious code injected. it's always the original filename (of the latest release of the actual mod)

edit: repo name for DSM is always Dankers-Skyblock-Mod

@5vl
Copy link
Author

5vl commented Aug 10, 2022

@EnderC00kiez Yeah the file name is always latest release, but that isn't hard seeing that the last release was over a year ago..

@cursefroge
Copy link

Now Sk1erLC has been deleted... Was that GitHub or just them? @5vl

@5vl
Copy link
Author

5vl commented Aug 10, 2022

I don't know. I hope it was github, because if it was them there'll probably be a new one very soon. Not that there wouldn't be if it was GH, it would maybe take a bit longer for them to know

@cursefroge
Copy link

If this naming pattern continues, we should be able to check https://github.com/search?q=Dankers-Skyblock-Mod&type=repositories to see if there are more - unless they are watching this thread

@cursefroge
Copy link

https://github.com/verifiedcode/Danker-s-Skyblock-Mod-v1.8.6-for-MC-1.8.9

Side note: wrong description lol

image

@cursefroge
Copy link

@cursefroge
Copy link

impersonator le thirde: https://github.com/Bowser00/SkyblockMod

@5vl
Copy link
Author

5vl commented Aug 10, 2022

Theyd be stupid to not watch this thread ngl

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants