Looks the Curseforge addon website was compromised. DO NOT UPDATE YOUR ADDONS!!!
Hello @everyone!
I’m afraid I’m the bearer of bad news tonight. It seems like CurseForge had a security breach and lots of accounts have been compromised, INCLUDING THOSE OF ADDON DEVELOPERS.
While this seem to have affected mostly Minecraft modpack developers, it can potentially also affect WoW addons developers. There are various reports of compromised accounts updating modpacks with malware and otherwise malicious code that would infect users PCs if they were to be downloaded, or even if they updated addons they already have to these “new” version.
DO NOT UPDATE OR DOWNLOAD ANY ADDON IN THE NEXT 24 HOURS THROUGH CURSEFORGENO MATTER THE METHOD, INCLUDING THE CURSEFORGE APP OR THEIR WEBSITE.
If you already have installed an update, please delete the mod files from your computer immediately and do a virus scan.
More information here:
https://www.reddit.com/r/feedthebeast/comments/142zxka/some_curseforge_accounts_might_be/
14 Likes
Just wanted to spread the word just in case. Keep your account and computer safe.
3 Likes
Well damn. I guess i wont be using curseforge anymore.
Where there is a will, there is a way. Its best to be suspicious of everything. Attack vectors aren’t obvious or they wouldn’t be suitable targets.
3 Likes
Umm I’m not sure which I updated. Should I just delete my whole addons folder and uninstall Curseforge? Would that be sufficient?
Lmao yeah just use one of those other services that’s 100% immune to security breaches
5 Likes
If you just download LUA addons for wow and install yourself from Curseforge that’s no problem. Kinda funny though that people are saying Curseforge is compromised NOW, when since they were bought by overwolf and their app runs on overwolf framework of w/e, you have all been willingly installing malware as it is.
I use the beta that just installs addons.
No the HC addon is 100% compromised. It will delete all of the fun off your computer and disable your ability to play with anyone in a MMO.
If left unchecked it will eventually leave entire servers empty of players.
2 Likes
Still waitin on your sub to run out. When is that happening? Can we get an eta please? I asked once nicely already.
2 Likes
Any idea how far back in time they were compromised?
1 Like
13 days and who knows, I just might have an extra couple minutes thereafter to hurt your delicate feelings with logic
Paper chain constructed. Itll be like christmas when i was a kid all over again. Enjoy your summer!
1 Like
Speaking of paper…your ego is paper thin. Might want to toughen up just a tad when conversing with adults.
So essentially, there’s no risk unless you download an add on that has that string in it.
TLDR: you’re fine, your add ons are fine, you can update them. Makes no sense the dev for details, bagnon, or any other add on would include this string.
I’ve never understood this argument for HC, how is this any different then no one talking to eachother in major capitals afk for hours on end? How is this different from the silent LFR, group finder groups, and m+?
It’s just another way to play the game for veterans who enjoy it, it’s not that deep.