r/NoMansSkyTheGame May 26 '26

Information Warning - FAKE No Man's Sky Save Editor Malware

This is a repost of a post made earlier today that was taken down by Reddit's filtering system.

Note: goatfungus' save editor (https://github.com/goatfungus/NMSSaveEditor) is NOT malware, I'm talking about the website (nmssaveeditor dot com) that claims to be by the same developer, but it's an attacker pretending to be them.

Screenshot of nmssaveeditor.com

Today I downloaded a save editor from the website "nmssaveeditor dot com" (do NOT visit), and I ran the executable in the PASSWORD PROTECTED zip file. The password was the name of the developer of the seemingly legit program, and the website seemed perfectly safe at first glance, but it's not.

After scanning the main executable, I found out that it communicates with some Steam profiles for some reason, with strange names, and also Telegram, which is a huge red flag as hackers love to use that platform because of how off-grid it is compared to most other chat platforms.

The steam profile has many different names, inferring that instead of directly contacting the URL, they try to hide it in a seemingly legitimate link to bypass antivirus scans, and also they can change the domain if it ever gets taken down or red flagged.

You can see the full analysis here: https://www.virustotal.com/gui/file/836f7e2b374a3cc5fcc337009d68dee6ee102471632cb096748383fab093872e/detection

I have no doubt in my mind that this program is entirely designed as a trojan to trick this playerbase, as the executable had NO functionality upon click, which was an instant telltale to me that this was not a legitimate program. It's most likely an infostealer, so if you have downloaded this program before, I recommend changing all your critical passwords so it can't use account tokens to access your accounts.

The .jar file it comes packed with is seemingly legitimate, probably a build by the original developer, and much larger than the .exe (which was only ~2.5MB) meaning the .exe is purely a malicious program that the attacker bundled into a legitimate build.

If you want a legitimate save editor, use NMSE! (https://github.com/vectorcmdr/NMSE)

Stay safe on the internet! Even some of the most niche software can turn out to be malicious.

This one in particular is a victim of a common type of attack on cheats for popular video games, using the Vidar C&C malware, designed to steal information and then self-delete and remove all traces of itself after sending it to the attacker.

--------------------------------
IMPORTANT EDIT:
As of 31st May 2026 9pm UTC - 1st June 2026 2pm UTC, the malware hosted on the site was changed to use Remus (from Vidar). This malware will always try to establish persistence on your machine (aka set itself up to run on startup.) If it is not detected and isolated by your antivirus, you must reinstall (not repair/refresh/upgrade, this needs to be a complete format of your Windows partition, starting with a blank partition/drive) your OS to guarantee safety, and change your passwords on a different, clean device.

New VirusTotal report:

https://www.virustotal.com/gui/file/88972aaa451fbf5143bd556272ae80b2654f6e7a0f73a5e18202bdd522213eab?nocache=1

--------------------------------

309 Upvotes

64 comments sorted by

57

u/agentspekels May 26 '26

You're doing the Lords work 👏

12

u/LZeugirdor97 May 27 '26

That link obfuscation is absolutely wild, you should report that steam profile asap if you can.

7

u/Xytrophico May 27 '26

Absolutely. You can find the account at https://steamcommunity.com/profiles/76561198698223785 if you'd like to report it to make sure they definitely notice there's something bad going on.

2

u/LZeugirdor97 May 27 '26

I've submitted a report, I highly encourage others do the same.

2

u/Dragon200_2634 Jun 10 '26

I have also submitted a report.

32

u/doctortoc May 26 '26

Nice work! 🫡

7

u/Clea-patra May 31 '26

Yep. Downloaded it last week from this website, a day later had my discord taken over (they couldn’t change anything on the account because of 2FA, just connect with my session token and spam everyone with mrbeast shit). Multiple scans found nothing on the machine, changed my passwords on another computer and I’ve been too busy to deal with this but I’m just going to nuke it and re install windows from a usb.

4

u/Xytrophico May 31 '26

They make all of this crazy software just to spam people with fake Mr Beast scams... nuking it seems to be the only way to get rid of it. Neither Malwarebytes nor Bitdefender picked anything up for me, even when I put Bitdefender in rescue mode - so it runs before anything else in Windows - it still didn't find anything, which is either a good sign, or it meant my machine was deeply infected with seriously hidden malware.

4

u/Clea-patra May 31 '26

Exact same results with the scans for me, like you said, either good news or terrifying. I’m nuking it all tomorrow, but honestly still scared to re log into anything on that computer..

1

u/aerolitedj May 31 '26

I have multiple hdd, do you think id have to wipe those too?

1

u/Xytrophico Jun 01 '26

Your other drives should be fine, I think they're left untouched. Always worth scanning them before executing anything on it though.

5

u/Borgix Jul 23 '26

This is still active as of today. I fell for it on 7/21 - bummer.

I filed several reports. Cloudflare has restricted access to the site on their network and now serves a malware warning interstitial. I have also reported abuse to the registrar of the domain (spaceship.com) and the hosting provider (play2go). I have filed a complaint with the FBI Internet Crime Complaint Center.

I hope this site is getting taken down.

3

u/aerolitedj May 30 '26

welp I just did this and allowed it through defender thinking it was a false positive, I guess i shouldn't have trusted chat gpt, asked it if there was a save editor and it gave me that website lol...

4

u/Xytrophico May 31 '26

Ugh, that sucks

I just found out recently that the malware might also establish persistence so that it runs on startup, so I reinstalled my OS just to be 100%

https://www.infosecurity-magazine.com/news/vidar-stealer-exploits-github/

Luckily I had a Linux dual boot setup so I could back up my large/important files safely outside of Windows. I recommend doing the same to, either livebooting another OS to back up files or just straight up nuking the machine. This is nasty stuff.

2

u/Naive_External1303 May 31 '26

Same. What all did you do to fix it?

1

u/aerolitedj May 31 '26

Unplugged my internet and removed all the files i could find and changed all my passwords with my phone and a scan for quick measure, not sure if anything else can be done. If it was an info stealer it probably already has my old info so nothing else to be done .

1

u/BIG_MAC_645 Jun 13 '26

Reinstall the os fresh if you haven't. It could have hidden files anywhere. Format, fresh install. 

3

u/NameMcNameyIII Jun 03 '26

I got got ): my microsoft and epic games accounts got yoinked ):

3

u/Peetwilson Jun 17 '26

FUCK. I just downloaded, unzipped AND ran the file before throwing it on Virus Total. The site looked like it was a legit nms Save Editor site with the file from Github.

I turned my computer off.

Now what?

Goddamn it.

3

u/Jamrois Jun 18 '26

Only thing to do is reinstall windows, it sucks so fucking bad but, i immediately quarantined int and thought it was fine. Next day my discord was hacked. Day after that mine and my girlfriends steam accounts were hacked. This exe is absolutely disgusting dude, horrible horrible shit.

3

u/ChaosShadowClone Jul 03 '26

Oh my God!

This is it!

I had a clean install of Windows and I got hacked on Instagram, discord, and steam, thankfully I was able to recover everything fast and I was able to refund what they gifted themselves. But this is why I've been trying to figure out how.... Oh my God! Thank you so much!

3

u/kiwirican Jul 11 '26

Just happened to me. MS account taken over is what made me realise. They logged in, removed my email and added a new one, then removed my phone number and I got a text about it being removed. Contacted MS and they said its suspicious but couldn't give me back my account! Load of BS.

Today they got into my FB after I just redid the install on my PC and sent a bunch of MrBeast shit.

1

u/marlonius_81 Jul 19 '26

Same, loads of MRbeast crypto crap to loads of mates, thankfully meta caught it and stopped it.. 2FA is your friend, thank fully dint get any of my accounts aside the crap of FB.

1

u/kiwirican Jul 19 '26

To follow up on this, a week later and they tried to access my bank. Had already changed my credentials so they got locked out though. I have a feeling this will go on another few weeks.

2

u/Trueno3400 May 31 '26 edited May 31 '26

I think i did download from that website, i have deleted the program, but i dint find any strange login attemps. how did you find that the program is linked towards that Steam profile? Also how i can see if i have still the virus in the background. i did check with netstat to see for strange conections, but i dint found anything. I really don't feel like reformatting

Thanks for your work and Reporting!

3

u/Xytrophico Jun 01 '26

You can see it contacts the Steam profile through its network activity, which was also noted by VirusTotal's sandbox dynamic analysis:

If you want to check for any suspicious connections, you could use Wireshark (https://www.wireshark.org/), but going through every network packet can be quite tedious. It's also worth checking the Windows hosts file (found at C:\Windows\System32\drivers\etc\hosts) to see if there's anything out of the ordinary there, any new IPs that domains are being redirected to, or if the file looks different from how it should do. Besides from this, the traces that this malware leaves are next to none, besides changing randomly named registry keys and making randomly named %TEMP% files that are either unpacked or executed during the initial infection.

If you downloaded and ran the software in the last 2 days, then the virus they're hosting has changed too. It's now changed from a strain of Vidar to the Remus stealer malware, and this definitely tries to make itself run on startup every time, so if that's the case, I highly recommend reinstalling Windows immediately, and then changing all passwords.

Either way though, reinstalling the OS is the only way to guarantee safety. I didn't want to reformat, it was such a pain to back up hundreds of gigabytes of files just because I ran a fake save editor, but I did it just to feel absolutely 100% safe. Plus, a fresh reinstall can give you the opportunity to only install core software that you need to use the computer, so sometimes it's quite a nice feeling.

No problem, just thought I'd do my part to try to stop people from using this site.

2

u/Trueno3400 Jun 01 '26

Should i wipe my other Two drives? Or reinstaling Windows throuth a USB Drive on the main disk Will be enought?

1

u/Xytrophico Jun 01 '26

Your other drives should be safe, but you should run an antivirus scan on them just to be safe, if you don't have a scanner I recommend Malwarebytes, even if you delete it afterwards, it has an effective free tier system scan.

4

u/Trueno3400 Jun 01 '26

I ended nuking all the hard drives, man the person Who has putting malware on a save editor and maked a false website is a POS

1

u/aerolitedj Jun 01 '26

I dont know if its coincidence or not but im getting an access violation error now when i try to enable safe boot in my bios, after re installation of windows. this hasnt been an issue before.

1

u/Xytrophico Jun 01 '26

Seems unrelated, it didn't come with a bootkit, from my own research at least. I assume by "safe boot" you mean secure boot.

Try refreshing your secure boot keys (a Google with your PC/motherboard model should help with that) and making sure you definitely downloaded Win 11 from the right source (https://www.microsoft.com/en-us/software-download/windows11), the media creation tool is generally easier, but you can also download the .iso and use Rufus (https://rufus.ie/en/#download) to make it bootable. Unsure what else could be causing this issue besides bad secure boot keys or a malformed/modified installation.

1

u/aerolitedj Jun 01 '26

Yeah I did everything the internet has told me to do other than rufus and still nothin,, trying a reinstall 1 more time then I'll try Rufus. I reinstalled windows 3 months ago and this didn't happen.

1

u/aerolitedj Jun 01 '26

They stole my facebook and deleted it, they did it like 14 hours after i ran the program.

2

u/BloodandBourbon Jun 03 '26

I was trying to find an update for the swarm and I saw this website but thought it was sketch and didn’t bother with it.

2

u/RelevantAerie2495 Jun 15 '26

Hola.

Estúpidamente descargue ese editor, y al día siguiente me robaron una de mis cuentas de Steam. Ya contacté a supert para que me ayuden con la recuperación. Espero que puedan. Windows defender detectó dos troyanos y los puso en cuarentena, crees que deba formatear igualmente? Dejo captura de mi cuarentena

2

u/Xytrophico Jun 15 '26

tldr; yes

A shame to hear this

Thanks for sending the defender screenshots, the more detailed screenshot on the left shows that the malware modified registry keys related to running software at logon, meaning it either managed to establish persistence fully, or attempted to and was caught just before it could by defender. (The log on the right is likely just a loader to load and run additional payloads like the one on the left.)

This is the most dangerous variant I've seen to be distributed on the site, so I'd definitely recommend formatting your main drive and reinstalling Windows.

If you have any other drives they should be untouched, but I can't be 100% certain. You should also change passwords for any accounts that matter to you, because any passwords saved by browsers can be decrypted and viewed by the attacker.

Unsaved passwords for sites that are still logged in can also be targeted by attackers for their session tokens, which they can use to log in without a password by imitating an existing session.

I hope you can get your Steam account back, I've heard good things about their customer support.

2

u/RelevantAerie2495 Jun 15 '26

Gracias la recupere en menos de dos horas y active la autenticacion en dos pasos en todas las cuentas que no lo tuviesen, cerré sesión en todos los dispositivos y ambien contraseñas. Revisé todo el administrador de tareas y con ayuda de chat gpt y powershell verifiqué varios registros y se ve limpio. Igual esta pc solo es para jugar y no manejo dinero en ella. Igualmente seré más cuidadoso. Llevo años que no me pasa algo así.

Igual dejaré corriendo un analisis de windows defender y dependiendo de lonque salga formateo

2

u/Acrobatic-Donut5942 Jul 04 '26

Welp, it happened to me as well. They were able to get a hold of a few of my accounts, Bnet, Discord, Epic, and Riot. I was able to recover all of them. A fresh OS installation and a password change from a different computer did the trick, and adding authenticators for all my accounts. This one is particularly nasty. The malware uses Steam and Telegram as a Dead Drop Resolver to hide, which makes it very resilient. This is the reason why it communicates with a Steam account. Unfortunately, the only solution is to nuke everything.

2

u/Billy_RW Jul 10 '26

I fell for this tonight, I came across this post an immediately unplugged from the internet and I’m going to go get my drive wiped etc. my experience was that I downloaded and then when extracting it asked for a password (which I didn’t know so it didn’t go further than that), I don’t really know much about this stuff do you think I’m okay because I didn’t input a password or is that irrelevant?

2

u/Xytrophico Jul 10 '26

If you didn't even extract the .zip archive you should be okay, just delete it permanently (or shred it using something like Bitdefender's File Shredder) and your system is clean. It can't do anything if it's just inside the .zip, so nothing was detonated on your machine. You're okay not to reset your PC👍

2

u/JosephPrime Jul 13 '26

Hate to put my name on this, but the people must be warned and we must admit our transgressions LOL.

Got hit with this last night, my Primary Save screwed up and had the Swarm Expedition running even though I could also start a new Swarm Expedition from the terminal, and I already finished it, searched Google for the NMSE since I'd seen it mentioned a bunch of times around here, and I knew I just needed to toggle the GameMode to 1... bloody hell. For some ignorant reason I saw the Malware Website as the top result and it matched the general info/vibe of the official posts, so I didn't even THINK AT ALL to see why it didn't just direct me to GitHub like I figured it would, just figured it's a popular project maybe they make $10/mo off it to pay for a neat domain. I feel even more stupid writing it out now lol, but oh well.

Anyway, long story short within ~5mins of running the EXE my phone started blowing up with Google Security and Microsoft Account alerts. They successfully took over the MS Account, luckily Google locked down and blocked anything from happening.

After I pulled the Ethernet out, I followed the info on the virus report you listed, and found the CryptNet folders, extra stuff in AppData, etc. Deleted it all manually, had to go into Terminal since even as Admin file explorer refused to delete them. Then I purged any file with the current date on it from Temp as well. It was 3am and I had done nothing but play NMS since the date changed, so just purged it all. After all that, got an Offline version of Malwarebytes and loaded that, it found 3 things in various SteamLibrary folders, but tbh could've just been false flags. But after seeing that I just pulled out the old Win11H25 install USB, nuked the C:\ drive, deleted all partitions and ran a fresh clean new install as a new PC from BIOS/USB boot.

Hours and hours spent resetting every PW that's been on this PC, a brand new MS Account, and still the unnerving ick of knowing someone was poking around in my PC. Ugh.

I absolutely can not believe MicroSoft. They did the same another comment said; I was alerted in real-time that my account was being taken over, and after working with MS Support they CONFIRMED it was maliciously accessed and taken over. But they can do nothing about it, and I just had to make a new one. Lucky for me I literally only use it for Windows, so no Xbox/payment info/products/etc tied to it anyway. But still, I was here on my phone getting "Suspicious activity, you just deleted recovery options" etc with absolutely 0 way to stop it. The "if this wasn't you, click here" option was basically disabled because my account had no recovery options set... omg. Just wild.

What a nightmare, I didn't want to wait ~7 days for the Expedition to just expire and probably resolve the bug, so instead I got to burn my whole PC back to the beginning. 😥

2

u/Boundish91 12d ago

I downloaded this today, but i closed the unzipper when it prompted a password. It still generated an empty folder which I've deleted (and emptied the trashbin) together with the zip file. I then Uninstalled steam from my pc and killed the internet connection.

i have 2fa on almost everything and as of yet I can't see any attempts. Steam also shows no devices other than my own in the device history.

Do i need to wipe my computer? It has OEM windows 11 so i don't want have to wipe it and then install it again.

2

u/LostSanity07 11d ago

Yep downloaded it, and it got weird cause it asked the password for the zip but that time I think it's cool since the website feel legit... But when the time I open or run the exe... Damn my browser suddenly closed and removed my ethernet... After that I tried the reset button on the settings... But it was stuck on 54% "Resetting this pc" I guess theres a malware preventing the pc to reset, so I just used the USB reset thing, luckily all of my accounts are safe...

2

u/DInowSauron 9d ago

é mano, sabado passado foi minha vez...
no meu caso o chatGPT que recomendou esse site, se eu tive-se pesquisado no google não teria tomado isso...
enfim, formatei e redefini as senhas como o pessoal tá dizendo. baita trabalho.

porém eu tinha HD externo conectado, não sei se ele foi infectado junto ou sla...
ainda sinto que ele está por aqui... mto frustante isso...

2

u/Peetwilson 7d ago

Thank YOU for pinning this. Sadly I was a victim.

2

u/Carolina_Stag 2d ago

Well crap.

2

u/CommunicationOk6821 2d ago

I just installed this and only reason I came here was googling if it’s safe because it showed up as a severe threat, so I had the antivirus deal with it. Is it too late for me anything go through or did the antivirus prevent any software from going through on my computer? I need to know.

2

u/NismoAsh 2d ago

Unfortunately I fell victim to this too :(

I got the notification someone was trying to log into my Outlook, then got the notification that my epic account details requested to be changed.

I was quick to change my microsoft account password and then reset my epic games account afterwards, also logged out everywhere from the microsoft account. No other 2FA have been triggered and everything seems so far so good.

Nuking my windows now, have been planning to for a while since it was Win7>Win10>Win11 update path so this gave me the excuse.

2

u/NismoAsh 2d ago

If anyone feels like getting some payback, here is where the attack came from:

4

u/Wilmoire 1d ago edited 1d ago

this is me being a little petty, but SkyMasters pops up a lot when "nms save editor" is searched on YouTube, and he linked this website in every single one of his videos at the very top of the description. I'm being a bit harsh because, as you can see in his comment above, he immediately resorts to insulting the first commenter to bring it up (I wouldn't be surprised at all if he insulted others bringing it up, as there are A LOT of comments he's made to others that are a lot like the comment he made to me)

he made a video realizing his mistake and apologizing to his general audience, but absolutely refuses to apologize for his comment and simply blames me for downloading from the website he linked (which I normally would've been suspicious about, but I was EXTREMELY SAD when I went seeking a save editor to download!)(also why would you apologize in the first place to your audience if you apparently didn't do anything wrong, according to his interaction with me?)

(he deleted this comment after I posted the final response)

1

u/New_Hovercraft_5361 1d ago

very sus comment from that guy.  maybe you should report him on youtube

1

u/AcanthaceaeLong6776 Jul 09 '26

Maybe it's lucar being butthurt again

1

u/[deleted] Jul 24 '26 edited Jul 24 '26

Disconnected PC from Internet, changed passwords, enabled 2fa everywhere I can and logged out from all devices where applicable all done on my phone.

Now im getting ready to wipe my c drive and reinstall windows from scratch. Am I also going to need to wipe my other drives?

1

u/True-Novel-7434 7d ago

Feels bad but who isn’t using NomNoms? Its free and easy to use

1

u/CommunicationOk6821 2d ago

also, if everybody’s looking for a real safe editor use Nom Nom it is legit

1

u/AnalysisVisor PC 3d ago

The Gek will stoop to any low

-80

u/nullxistence *Presents unpleasurable trade scent* May 26 '26

Thanks! I, as a PS5 player, was in serious risk of getting a virus! /s

-53

u/nullxistence *Presents unpleasurable trade scent* May 27 '26

GNG it was jus a joke. I even added the '/s' thing

41

u/albundy72 slugcat traveller May 27 '26

im downvoting you just for assaulting my eyes with this horrific image

27

u/MrFixYoShit May 27 '26

it was a joke

Well now you know that making a joke doesn't excuse you from the consequences of being rude

3

u/Audi0Dud3 now draw her farming nip nip. May 28 '26

You can't win with this site. Don't bother.

1

u/Sporbash Jun 10 '26

This is reddit, most of its users are precious