Jump to content

Recommended Posts

Hello everyone!

I'm facing a critical issue in Don't starve together and want to warm the community. 


A player named [removed] has created and is distributing a malicious exploit

Unlike typical scams, this tool completely destroys skins (forces unbundling)

My partner fell victim: after being blackmailed, their entire skin inventory was wiped (irrefutable evidence available)

 

Key Facts:

- This is not hacking in the traditional sense — skins aren’t stolen but intentionally destroyed

- The exploit abuses game vulnerabilities for mass inventory deletion

- The standard restoration process is unacceptably slow for losses of this scale

Required Actions:

If you’ve encountered this player/exploit — comment below to document cases

For Developers, Moderators:

1. Is emergency skin restoration possible for victims?

2. Is an urgent patch planned to fix the vulnerability?

3. Will there be an official player warning?

4. Can you prioritize helping me partner? Their collection was fully wiped.

Their steam ID: 76561199092566482

Their klei account ID: KU_6BQklMnC

IMG_20250621_203716_455.jpg

IMG_20250621_203715_894.jpg

IMG_20250621_203716_223.jpg

Edited by JoeW
Removed accusatory naming from main post
  • Like 1
  • Sad 1
  • Health 1
  • Sad Dupe 8

Wow, that's awful. I hope klei takes action against the player and restores your skins. I wouldn't feel comfortable buying skins if I thought this was an issue I could run into. Sometimes it's nice to be on console.

3 hours ago, Radicaljoe said:

Was this a mod your friend downloaded or something?

This please, care to give more details about how this happened?

  • Did another player just randomly tell your friend they were going to lose all skins?
  • Did your friend have any skin related mod, or was playing at some specific modded server?
  • Did your friend enter their steam credentials or klei credentials at some link request?
  • Like 12
  • Developer

We store audit logs of all actions on skins, so I'm not very worried about the repair part. It may take time but all the information is there.

The thing that I need more detail on is how this malware got access to the affected player's inventory - we don't want other people being affected.

  • Like 40
  • Big Ups 1
38 minutes ago, nome said:

Мы храним логи аудита всех действий на скинах, поэтому я не очень переживаю за ремонтную часть. Это может занять время, но вся информация есть.

Мне нужно подробнее рассказать о том, как эта вредоносная программа получила доступ к инвентарю пострадавшего игрока - мы не хотим, чтобы пострадали другие люди.

Thank you for your response! Could I contact you directly to provide more details?

5 hours ago, ShadowDuelist said:

Пожалуйста, не могли бы вы рассказать подробнее о том, как это произошло?

  • Другой игрок просто случайно сказал вашему другу, что потеряет все скины?
  • Был ли у вашего друга какой-то мод, связанный со скинами, или он играл на каком-то определенном модифицированном сервере?
  • Ваш друг вводил свои учетные данные Steam или klei по запросу какой-то ссылки?

Here are some details:
The virus spreads from an infected player to others just by joining the same server. Thousands of players have been infected without even realizing it. You're only at risk if you or your friends played on random public servers.

This has been happening since January—be careful.

Here’s a quote from someone who knows more about this:
"And instead of explaining things properly, he created a virus that infected thousands of players. The malware spread when players joined worlds, monitored them, gave [removed] admin rights, allowed him to ban players, spawn resources, spam any messages, and even delete entire worlds."

Edited by JoeW
Removed names
  • Like 1
54 minutes ago, kipper0k said:

I think it's funny, I'm already banned for doing this in January, and the methods I used to do it were covered up

 

I don't think anyone cares. Why do you have to brag about doing something like this?

Also, all you did previously was make it more difficult for modders by trying to show off that you can exploit the code.

  • Like 26
1 hour ago, Bumber64 said:

Do you have an example of an infected mod? This all seems very hearsay.

OP probably contacted the devs directly by now, and this will probably be solved privately.

Which is the ideal solution IMO. There is no reason to tell people about a security vulnerability openly and in public. It's best to contact devs about it directly so that they can fix it before more people find out how to exploit it. Talking about it in public might be enough to let more bad faith actors figure out how to use it.

  • Like 5
  • Sanity 1

Just happened to me, when I saw this I quickly disabled all my client mods and it stopped.

The virus tried to bought high heels to remove my spools, it managed to buy only one high heels. I was able to rollback all my skins but it took me 1 hour to rollback all of them.

In short, this gave me a small heart attack.

  • Sad 4
  • Big Ups 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
  • Create New...