Forum Discussion

luthienrising's avatar
2 years ago

CURRENT ISSUE! Malicious Script Mods and Other Malware

CURRENT INCIDENT:  Malicious ts4script files in multiple compromised accounts on Mod the Sims and an 18+ site, beginning March 1, 2026. 

Posts with full details: 

Multiple Mod the Sims accounts compromised. Malicious ts4script files have been uploaded to multiple mods, including to mods/CC that should not have one. Delete immediately and run a full-system malware and virus check. 

18+ website also compromised. If you have recently downloaded an 18+ mod from an 18+ website and you don't use ModGuard, check if you've been infected with malware: Look in your Sims 4 install location for a file called "out.exe" (or "out" if extensions are hidden). Do not run the file. Do this:

  1. Delete the file
  2. Delete recently downloaded 18+ mods
  3. Empty your Recycle Bin to permanently delete them
  4. Run a full virus and malware scan 
  5. Change your passwords

 

See see the section in How to Use Mods and CC about "Safe Simming" for advice on how to avoid downloading compromised files. Download TwistedMexi's Modguard mod (from his website or Curseforge) to help protect you from the file you thought was okay, even after being cautious.

 

*****************************************************************************************

 

January 2024 Incident

Beginning as early as mid-January 2024, we began seeing Sims 4 script mods with malicious executable .exe code hidden in them. 

 

The mods masqueraded as being from existing creators or from a brand-new creator with a name similar to an existing one. In one known case, it appears that a creator’s account was hacked to update the creator’s own mod page. These mods also presented themselves as being previously existing mods. (Mac users: Because this is .exe code, it won’t affect you, but may produce LEs.)

Mods known to have been compromised

  • "PimpMySims4" (impersonated) – Cult Mod – was on Mod the Sims; now removed
  • MySims4 – "Social Events - Unlimited Time" – was on Curseforge; now removed
  • MSQSims (hacked) – on The Sims Resource, Feb. 5-8; all removed
    • Mood Cheat Menu
    • Motherlode Menu
    • Seasons Cheat Menu
    • Weather Forecast Cheat Menu
  • PlayersWonderland (hacked) – Mouth Preset N16 ts4script file – on The Sims Resource, now removed
  • V1 of an adult mod, with a January file date – on LoversLab

How to check your system for the January 2024 malware

To see if your system has been affected by the malicious code:

  1. select Windows-R
  2. In the window that opens, type this:

%AppData%\Microsoft\Internet Explorer\UserData

  1. In the folder that opens, look for files called Updater.exe and/or Main.exe.

If you are affected

If you had one of these files, assume that any sensitive data on your PC may be compromised and take the steps below:

  1. Clear your system for this specific virus. (See below.) This must be done FIRST.
  2. If you have the Discord app or a cryptocurrency wallet app, uninstall them. This is important if not obvious: Starting these can trigger an attempt to reinstall this malware.
  3. Change your passwords.
  4. Add two-factor authentication where available.
  5. If you had saved credit card or similar information to a web browser, remove it and find out from your financial institution (or other relevant site) what action to take next.
  6. Reinstall Discord and cryptocurrency wallet apps from fresh downloads.
  7. Learn more about keeping your data secure in the future: https://answers.ea.com/t5/EA-Services-General-Questions/Answers-HQ-Online-Security-Newsletter-January/m-p/13449052/thread-id/447422

To clear your system:

  1. Download this fix created by Maxis mod-host partner Curseforge: SimsVirusCleaner
  2. Double-click the SimsVirusCleaner.exe file in your Downloads folder tor run it.
  3. This is a good time to run a general virus/malware scan on your computer.

More things to know

  • Curseforge and The Sims Resource updated their file screening for this method of malware inclusion.
  • Type of mods affected: The least likely mods to be affected were mods that are only .package files and mods uploaded by mod creators on Patreon or their own sites. Most Sims 4 mods are not script mods and aren’t doing anything requiring a ts4script file.
  • Downloaded folders: Assume that any folder containing a collection of mods might include a compromised mod containing code that can steal your passwords, your banking info, and much more. Do NOT download and install these collections. If you have done so at any time since mid-January, check your system.
  • New prevention/detection Sims 4 tool: TwistedMexi released a tool called ModGuard.

April 2024 Incident

[April 7, 2024] Malware via a mod that downloaded as only a text file with a link.

Known cases:

  • "S4 CAS Tools" on Nexus from user fubruss (the real mod is on Mod the Sims, from the late CmarNYC, dated 18 March 2023)
  • “Loading Screen Randomizer” on Nexus from user fubruss (the real mod is on Mod the Sims, from Tesuto , dated 9 January 2024)

Do NOT follow the links in text files. Do NOT download other files or follow links from this user. No legitimate mod download will EVER consist of only a text file (a file ending in .txt).  

If you downloaded either of these, delete them and run a virus scan. NOTE: This type malware does NOT require that you run the game for it to install itself, and is not what ModGuard is designed to detect and stop.


November 2024 Incident

On November 5, 2024, on Mod the Sims, someone uploaded malicious versions of at least four mods. Unlike the earlier incident, no new accounts were involved, and one of the accounts breached was TwistedMexi's. No other compromised mods were found. It is not yet known what the effect of any malware included or called up was, so assume it's very bad.

What to do

  • If you downloaded any mods with .ts4script files from Mod the Sims on November 5, delete the mod and run a virus scan.
  • If you don't already have it, download TwistedMexi's tool ModGuard. It will not protect against all possible script-file exploits, but it will help. Note that your other system protections cannot see what's in a .ts4script file.

 

April 13, 2025 incident 

Some SimFileShare CC compromised 

Do not download mods from SimAndy or TheNinthWaveSim or Pixelunivairse mods/CC from SimFileShare. The accounts are compromised. Files present include an executable (.exe) file presumed to be malicious. If you downloaded files from these creators after about April 11, delete them and run a virus scan

The owner of SFS has removed all known compromised files, and SFS is permitting file uploads again. Please remain cautious about what you download, especially files that were updated in early April 2025.

 

March 2026 incident 

Multiple Mod the Sims accounts compromised. Ts4script files uploaded, including to mods/CC that should not have one. Files contents clearly malicious.  If you downloaded any ts4script files from Mod the Sims beginning March 1, 2026, delete immediately and run a full-system malware and virus check. All compromised files have been removed. An 18+ mod-hosting website is also compromised.

If you have recently downloaded an 18+ mod from an 18+ website and you don't use ModGuard, check if you've been infected with malware: Look in your Sims 4 install location for a file called "out.exe" (or "out" if extensions are hidden). Do not run the file. Do this:

  1. Delete the file
  2. Delete recently downloaded 18+ mods
  3. Empty your Recycle Bin to permanently delete them
  4. Run a full virus and malware scan 
  5. Change your passwords

 

Current Impact of Incidents on Mod Update News

  • Updates of mods/CC hosted only on Mod the Sims are on pause. 

 

- updated March 2, 2026

20 Replies

Replies have been turned off for this discussion
  • luthienrising's avatar
    luthienrising
    Hero+
    1 year ago

    November 2024 Incident

    Security breach at Mod the Sims; malicious script files uploaded to known modders' mods

    On November 5, 2024, a security breach at Mod the Sims enabled someone to upload malicious versions of at least 4 mods. Unlike the earlier incident, no new accounts were involved, and one of the accounts breached was TwistedMexi's. It's not known (as of November 6) if any updates from before November 5 are also compromised. It is not yet known what the effect of any malware included or called up is, so assume it's very bad.

    What to do NOW

    • If you downloaded any mods with .ts4script files from Mod the Sims on November 5, delete the mod and run a virus scan.
    • If you don't already have it, download TwistedMexi's tool ModGuard. It will not protect against all possible script-file exploits, but it will help. Note that your other system protections cannot see what's in a .ts4script file.

    Downloading from Mod the Sims

    I cannot in good conscience recommend that Simmers download script mods (any mod with a .ts4script file) from Mod the Sims, as this is the second incident there in a year. If you decide to continue using Mod the Sims, look at the files in the Zip folder. If they include a .ts4script file, find a different site the modder uses. Many modders have multiple places they upload, such as Patreon, Curseforge, itchio, or their own website. 

    IMPORTANT: Changes to Mod Update News

    • I will no longer report on updates of mods/CC hosted only on Mod the Sims. The process of verifying that an upload is legitimate can be complex and time consuming, involving decompiling code, and I value my time. I didn't take that added time on November 5, and reports of these mod updates were on this site for at least an hour.
    • I will continue to report broken mods even if they're on Mod the Sims. (Note that this doesn't mean I'll start reporting mods not previously reported here. There are still reasons that some mods/creators are not reported about on EA sites.)
    • The mod list for November has already been adjusted to direct you to alternative places modders host mods.
    • The mod list "Creator News" will report when modders using MTS add new hosts for their mods.
  • April 13, 2025 

    SimAndy mods/CC compromised 

    Do not download SimAndy mods/CC from SimFileShare. The account is compromised. Files present include an executable file presumed to be malicious. 

  • April 14, 2025

    Some custom content downloads by SimAndy and TheNinthWaveSim on SimFileShare are compromised with an .exe (executable) file. Do NOT download them. If you did download any files from SimAndy in the last day or so, delete them and run a virus scan.

    TIP: Always look at the files that you download and that you extract from a zip or rar. It should make sense to you that that hair CC is not an executable program and should not have .exe or script files.

  • April 17

    • Pixelunivairse was told by SimFileShare that someone accessed their account. It’s not clear if uploads were replaced with malware executable files, but it looks like SFS has removed a fair bit of content just in case. If you recently downloaded files from Pixelunivairse, check for anything that’s not a .package file, delete, and run a virus scan.
  • April 17

    It's now confirmed that ALL mods on SimFileShare from Pixelunivairse are compromised. They are replaced with .exe files and should be presumed to be serious malware. Do NOT download them. If you are still using SimFileShare, download ONLY older files -- say, before April 2025. 

  • April 24, 2025

    The owner of SFS has removed all known compromised files, and SFS is permitting file uploads again. Please remain cautious about what you download, especially files that were updated in early April 2025.

  • March 1, 2026

    Do NOT download new updates of NateTheLoser’s mods on Mod the Sims. Nate has confirmed with me that he NOT updated these. Script files appear almost certainly to be malicious.

    NO 2026 mod files on a NateTheLoser account is a legitimate upload.

    If you installed any of these mods, delete them immediately and run a full system scan for malware and viruses. Nate has regained control of his account and reuploaded the original, safe files.

    affected mods:

    • Chat Pack
    • Coming Out
    • Misery Traits

     

    Mod news impact: MTS-hosted mod updates already are checked by me for possible issues before announcing their updates, which is why this information is getting to you quickly. Clearly, there is good reason for this practice. 

    Further advice: Do not download new script mods from Mod the Sims. All creators using Mod the Sims should be also posting on a second site that has better security protocols.

     

  • ******************

    WARNING UPDATE, March 2026:

    This is now a multi-account compromise. Do not download ANY updated or new mods from Mod the Sims. 

    If you downloaded ANY .ts4script file from Mod the Sims beginning March 1, 2026, DELETE IT and run a system-wide malware and virus scan.

    And remember basic Safe Simming: CC objects and CAS items do NOT have ts4script files!

     

     

    affected accounts (as of time of posting):

    • NateTheLoser (account control regained as of time of posting, malicious files removed)
    • PurrSimity
    • JellyHeadDimbulb
    •  

    ******************

  • March 2: Malicious Mod Update

     

    RE MOD THE SIMS: The compromised files have all been removed. However, you can’t tell that from the “Information” tab, and I advise using that tab before downloading files so you know whether there’s a script file. The owner of the site has added a feature to check IP addresses of creators logging in. I do not consider this equivalent to using two-factor authentication, and it’s likely to lock out creators who’s IP address changes for valid reasons. I am not yet satisfied enough with the situation at MTS to recommending downloading new mods or updated mods from there, and I will not be reporting updates to MTS-only mods for the time being. If you’re a creator who posts only to MTS, get a second place to host your mods.

     

    ADDITIONAL WARNING RE. 18+ MODS: Another malicious mod, from a different website, has been identified. This is an 18+ mod and I will not be naming it here.

     

    INSTALL MODGUARD. The identification was made because a player had installed TwistedMexi’s Modguard in their Mods folder. Modguard helps protect you from some kinds of compromised files and it sends info about compromised files when it detects them, so that we can tell everyone else about them. Download Modguard from the TwistedMexi website or from Curseforge.

     

    PRACTICE SAFE MOD/CC SOURCING. Because this issue has now spread to multiple mod hosts, be extra cautious about what you download. That includes new mods/CC from new creators, new files from long-inactive creators, files updated with no info where there usually is some, files uploaded to a new site for that creator, CC with non-package files, etc., etc. Read my advice on “Safe Simming” in the pinned “How to” post: https://forums.ea.com/discussions/the-sims-4-mods-and-custom-content-en/re-info-how-to-use-mods-and-cc/9360654

     

  • March 2: Malicious Mod Update (#2)

    If you have recently downloaded an 18+ mod from an 18+ website and you don't use ModGuard, check if you've been infected with the mod's malware: Look in your Sims 4 install location for a file called "out.exe" (or "out" if extensions are hidden). Do not run the file. Do this:

    1. Delete the file
    2. Delete recently downloaded 18+ mods
    3. Empty your Recycle Bin to permanently delete them
    4. Run a full virus and malware scan 
    5. Change your passwords

Featured Places

Node avatar for The Sims 4 Mods & Custom Content

The Sims 4 Mods & Custom Content

Find tips, tutorials and troubleshooting for mods and custom content, and The Sims 4 patch files here.Latest Activity: 1 hour ago
16,679 Posts