Forum Discussion

luthienrising's avatar
2 years ago

Malicious Script Mods and Other Malware


CURRENT INCIDENT:  Some SimFileShare accounts compromised. See here.

 

January 2024 Incident

Beginning as early as mid-January 2024, we began seeing Sims 4 script mods with malicious executable .exe code hidden in them. 

 

The mods masqueraded as being from existing creators or from a brand-new creator with a name similar to an existing one. In one known case, it appears that a creator’s account was hacked to update the creator’s own mod page. These mods also presented themselves as being previously existing mods. (Mac users: Because this is .exe code, it won’t affect you, but may produce LEs.)

Mods known to have been compromised

  • "PimpMySims4" (impersonated) – Cult Mod – was on Mod the Sims; now removed
  • MySims4 – "Social Events - Unlimited Time" – was on Curseforge; now removed
  • MSQSims (hacked) – on The Sims Resource, Feb. 5-8; all removed
    • Mood Cheat Menu
    • Motherlode Menu
    • Seasons Cheat Menu
    • Weather Forecast Cheat Menu
  • PlayersWonderland (hacked) – Mouth Preset N16 ts4script file – on The Sims Resource, now removed
  • V1 of an adult mod, with a January file date – on LoversLab

How to check your system for the January 2024 malware

To see if your system has been affected by the malicious code:

  1. select Windows-R
  2. In the window that opens, type this:

%AppData%\Microsoft\Internet Explorer\UserData

  1. In the folder that opens, look for files called Updater.exe and/or Main.exe.

If you are affected

If you had one of these files, assume that any sensitive data on your PC may be compromised and take the steps below:

  1. Clear your system for this specific virus. (See below.) This must be done FIRST.
  2. If you have the Discord app or a cryptocurrency wallet app, uninstall them. This is important if not obvious: Starting these can trigger an attempt to reinstall this malware.
  3. Change your passwords.
  4. Add two-factor authentication where available.
  5. If you had saved credit card or similar information to a web browser, remove it and find out from your financial institution (or other relevant site) what action to take next.
  6. Reinstall Discord and cryptocurrency wallet apps from fresh downloads.
  7. Learn more about keeping your data secure in the future: https://answers.ea.com/t5/EA-Services-General-Questions/Answers-HQ-Online-Security-Newsletter-January/m-p/13449052/thread-id/447422

To clear your system:

  1. Download this fix created by Maxis mod-host partner Curseforge: SimsVirusCleaner
  2. Double-click the SimsVirusCleaner.exe file in your Downloads folder tor run it.
  3. This is a good time to run a general virus/malware scan on your computer.

More things to know

  • Curseforge and The Sims Resource updated their file screening for this method of malware inclusion.
  • Type of mods affected: The least likely mods to be affected were mods that are only .package files and mods uploaded by mod creators on Patreon or their own sites. Most Sims 4 mods are not script mods and aren’t doing anything requiring a ts4script file.
  • Downloaded folders: Assume that any folder containing a collection of mods might include a compromised mod containing code that can steal your passwords, your banking info, and much more. Do NOT download and install these collections. If you have done so at any time since mid-January, check your system.
  • New prevention/detection Sims 4 tool: TwistedMexi released a tool called ModGuard.

April 2024 Incident

[April 7, 2024] Malware via a mod that downloaded as only a text file with a link.

Known cases:

  • "S4 CAS Tools" on Nexus from user fubruss (the real mod is on Mod the Sims, from the late CmarNYC, dated 18 March 2023)
  • “Loading Screen Randomizer” on Nexus from user fubruss (the real mod is on Mod the Sims, from Tesuto , dated 9 January 2024)

Do NOT follow the links in text files. Do NOT download other files or follow links from this user. No legitimate mod download will EVER consist of only a text file (a file ending in .txt).  

If you downloaded either of these, delete them and run a virus scan. NOTE: This type malware does NOT require that you run the game for it to install itself, and is not what ModGuard is designed to detect and stop.


November 2024 Incident

On November 5, 2024, on Mod the Sims, someone uploaded malicious versions of at least four mods. Unlike the earlier incident, no new accounts were involved, and one of the accounts breached was TwistedMexi's. No other compromised mods were found. It is not yet known what the effect of any malware included or called up was, so assume it's very bad.

What to do

  • If you downloaded any mods with .ts4script files from Mod the Sims on November 5, delete the mod and run a virus scan.
  • If you don't already have it, download TwistedMexi's tool ModGuard. It will not protect against all possible script-file exploits, but it will help. Note that your other system protections cannot see what's in a .ts4script file.

 

April 13, 2025 incident 

Some SimFileShare CC compromised 

Do not download mods from SimAndy or TheNinthWaveSim or Pixelunivairse mods/CC from SimFileShare. The accounts are compromised. Files present include an executable (.exe) file presumed to be malicious. If you downloaded files from these creators after about April 11, delete them and run a virus scan

The owner of SFS has removed all known compromised files, and SFS is permitting file uploads again. Please remain cautious about what you download, especially files that were updated in early April 2025.

 

Current Impact of Incidents on Mod Update News

  • Updates of mods/CC hosted only on Mod the Sims or only on SimFileShare may be delayed. 

 

- updated April 24, 2025 

16 Replies

Replies have been turned off for this discussion
  • luthienrising's avatar
    luthienrising
    Hero+
    9 months ago

    November 2024 Incident

    Security breach at Mod the Sims; malicious script files uploaded to known modders' mods

    On November 5, 2024, a security breach at Mod the Sims enabled someone to upload malicious versions of at least 4 mods. Unlike the earlier incident, no new accounts were involved, and one of the accounts breached was TwistedMexi's. It's not known (as of November 6) if any updates from before November 5 are also compromised. It is not yet known what the effect of any malware included or called up is, so assume it's very bad.

    What to do NOW

    • If you downloaded any mods with .ts4script files from Mod the Sims on November 5, delete the mod and run a virus scan.
    • If you don't already have it, download TwistedMexi's tool ModGuard. It will not protect against all possible script-file exploits, but it will help. Note that your other system protections cannot see what's in a .ts4script file.

    Downloading from Mod the Sims

    I cannot in good conscience recommend that Simmers download script mods (any mod with a .ts4script file) from Mod the Sims, as this is the second incident there in a year. If you decide to continue using Mod the Sims, look at the files in the Zip folder. If they include a .ts4script file, find a different site the modder uses. Many modders have multiple places they upload, such as Patreon, Curseforge, itchio, or their own website. 

    IMPORTANT: Changes to Mod Update News

    • I will no longer report on updates of mods/CC hosted only on Mod the Sims. The process of verifying that an upload is legitimate can be complex and time consuming, involving decompiling code, and I value my time. I didn't take that added time on November 5, and reports of these mod updates were on this site for at least an hour.
    • I will continue to report broken mods even if they're on Mod the Sims. (Note that this doesn't mean I'll start reporting mods not previously reported here. There are still reasons that some mods/creators are not reported about on EA sites.)
    • The mod list for November has already been adjusted to direct you to alternative places modders host mods.
    • The mod list "Creator News" will report when modders using MTS add new hosts for their mods.
  • April 13, 2025 

    SimAndy mods/CC compromised 

    Do not download SimAndy mods/CC from SimFileShare. The account is compromised. Files present include an executable file presumed to be malicious. 

  • April 14, 2025

    Some custom content downloads by SimAndy and TheNinthWaveSim on SimFileShare are compromised with an .exe (executable) file. Do NOT download them. If you did download any files from SimAndy in the last day or so, delete them and run a virus scan.

    TIP: Always look at the files that you download and that you extract from a zip or rar. It should make sense to you that that hair CC is not an executable program and should not have .exe or script files.

  • April 17

    • Pixelunivairse was told by SimFileShare that someone accessed their account. It’s not clear if uploads were replaced with malware executable files, but it looks like SFS has removed a fair bit of content just in case. If you recently downloaded files from Pixelunivairse, check for anything that’s not a .package file, delete, and run a virus scan.
  • April 17

    It's now confirmed that ALL mods on SimFileShare from Pixelunivairse are compromised. They are replaced with .exe files and should be presumed to be serious malware. Do NOT download them. If you are still using SimFileShare, download ONLY older files -- say, before April 2025. 

  • April 24, 2025

    The owner of SFS has removed all known compromised files, and SFS is permitting file uploads again. Please remain cautious about what you download, especially files that were updated in early April 2025.

About The Sims 4 Mods & Custom Content

Find expert tips, troubleshooting help, tutorials for mods and custom content, and The Sims 4 patch files in our forum.15,625 PostsLatest Activity: 2 hours ago