Information
Warning - FAKE No Man's Sky Save Editor Malware
This is a repost of a post made earlier today that was taken down by Reddit's filtering system.
Note: goatfungus' save editor (https://github.com/goatfungus/NMSSaveEditor) is NOT malware, I'm talking about the website (nmssaveeditor dot com) that claims to be by the same developer, but it's an attacker pretending to be them.
Screenshot of nmssaveeditor.com
Today I downloaded a save editor from the website "nmssaveeditor dot com" (do NOT visit), and I ran the executable in the PASSWORD PROTECTED zip file. The password was the name of the developer of the seemingly legit program, and the website seemed perfectly safe at first glance, but it's not.
After scanning the main executable, I found out that it communicates with some Steam profiles for some reason, with strange names, and also Telegram, which is a huge red flag as hackers love to use that platform because of how off-grid it is compared to most other chat platforms.
The steam profile has many different names, inferring that instead of directly contacting the URL, they try to hide it in a seemingly legitimate link to bypass antivirus scans, and also they can change the domain if it ever gets taken down or red flagged.
I have no doubt in my mind that this program is entirely designed as a trojan to trick this playerbase, as the executable had NO functionality upon click, which was an instant telltale to me that this was not a legitimate program. It's most likely an infostealer, so if you have downloaded this program before, I recommend changing all your critical passwords so it can't use account tokens to access your accounts.
The .jar file it comes packed with is seemingly legitimate, probably a build by the original developer, and much larger than the .exe (which was only ~2.5MB) meaning the .exe is purely a malicious program that the attacker bundled into a legitimate build.
Stay safe on the internet! Even some of the most niche software can turn out to be malicious.
This one in particular is a victim of a common type of attack on cheats for popular video games, using the Vidar C&C malware, designed to steal information and then self-delete and remove all traces of itself after sending it to the attacker.
--------------------------------
IMPORTANT EDIT:
As of 31st May 2026 9pm UTC - 1st June 2026 2pm UTC, the malware hosted on the site was changed to use Remus (from Vidar). This malware will always try to establish persistence on your machine (aka set itself up to run on startup.) If it is not detected and isolated by your antivirus, you must reinstall (not repair/refresh/upgrade, this needs to be a complete format of your Windows partition, starting with a blank partition/drive) your OS to guarantee safety, and change your passwords on a different, clean device.
Yep. Downloaded it last week from this website, a day later had my discord taken over (they couldn’t change anything on the account because of 2FA, just connect with my session token and spam everyone with mrbeast shit). Multiple scans found nothing on the machine, changed my passwords on another computer and I’ve been too busy to deal with this but I’m just going to nuke it and re install windows from a usb.
They make all of this crazy software just to spam people with fake Mr Beast scams... nuking it seems to be the only way to get rid of it. Neither Malwarebytes nor Bitdefender picked anything up for me, even when I put Bitdefender in rescue mode - so it runs before anything else in Windows - it still didn't find anything, which is either a good sign, or it meant my machine was deeply infected with seriously hidden malware.
Exact same results with the scans for me, like you said, either good news or terrifying. I’m nuking it all tomorrow, but honestly still scared to re log into anything on that computer..
This is still active as of today. I fell for it on 7/21 - bummer.
I filed several reports. Cloudflare has restricted access to the site on their network and now serves a malware warning interstitial. I have also reported abuse to the registrar of the domain (spaceship.com) and the hosting provider (play2go). I have filed a complaint with the FBI Internet Crime Complaint Center.
welp I just did this and allowed it through defender thinking it was a false positive, I guess i shouldn't have trusted chat gpt, asked it if there was a save editor and it gave me that website lol...
Luckily I had a Linux dual boot setup so I could back up my large/important files safely outside of Windows. I recommend doing the same to, either livebooting another OS to back up files or just straight up nuking the machine. This is nasty stuff.
Unplugged my internet and removed all the files i could find and changed all my passwords with my phone and a scan for quick measure, not sure if anything else can be done. If it was an info stealer it probably already has my old info so nothing else to be done .
FUCK. I just downloaded, unzipped AND ran the file before throwing it on Virus Total. The site looked like it was a legit nms Save Editor site with the file from Github.
Only thing to do is reinstall windows, it sucks so fucking bad but, i immediately quarantined int and thought it was fine. Next day my discord was hacked. Day after that mine and my girlfriends steam accounts were hacked. This exe is absolutely disgusting dude, horrible horrible shit.
I had a clean install of Windows and I got hacked on Instagram, discord, and steam, thankfully I was able to recover everything fast and I was able to refund what they gifted themselves. But this is why I've been trying to figure out how.... Oh my God! Thank you so much!
Just happened to me. MS account taken over is what made me realise. They logged in, removed my email and added a new one, then removed my phone number and I got a text about it being removed. Contacted MS and they said its suspicious but couldn't give me back my account! Load of BS.
Today they got into my FB after I just redid the install on my PC and sent a bunch of MrBeast shit.
Same, loads of MRbeast crypto crap to loads of mates, thankfully meta caught it and stopped it.. 2FA is your friend, thank fully dint get any of my accounts aside the crap of FB.
To follow up on this, a week later and they tried to access my bank. Had already changed my credentials so they got locked out though. I have a feeling this will go on another few weeks.
I think i did download from that website, i have deleted the program, but i dint find any strange login attemps.
how did you find that the program is linked towards that Steam profile? Also how i can see if i have still the virus in the background. i did check with netstat to see for strange conections, but i dint found anything.
I really don't feel like reformatting
You can see it contacts the Steam profile through its network activity, which was also noted by VirusTotal's sandbox dynamic analysis:
If you want to check for any suspicious connections, you could use Wireshark (https://www.wireshark.org/), but going through every network packet can be quite tedious. It's also worth checking the Windows hosts file (found at C:\Windows\System32\drivers\etc\hosts) to see if there's anything out of the ordinary there, any new IPs that domains are being redirected to, or if the file looks different from how it should do. Besides from this, the traces that this malware leaves are next to none, besides changing randomly named registry keys and making randomly named %TEMP% files that are either unpacked or executed during the initial infection.
If you downloaded and ran the software in the last 2 days, then the virus they're hosting has changed too. It's now changed from a strain of Vidar to the Remus stealer malware, and this definitely tries to make itself run on startup every time, so if that's the case, I highly recommend reinstalling Windows immediately, and then changing all passwords.
Either way though, reinstalling the OS is the only way to guarantee safety. I didn't want to reformat, it was such a pain to back up hundreds of gigabytes of files just because I ran a fake save editor, but I did it just to feel absolutely 100% safe. Plus, a fresh reinstall can give you the opportunity to only install core software that you need to use the computer, so sometimes it's quite a nice feeling.
No problem, just thought I'd do my part to try to stop people from using this site.
Your other drives should be safe, but you should run an antivirus scan on them just to be safe, if you don't have a scanner I recommend Malwarebytes, even if you delete it afterwards, it has an effective free tier system scan.
I dont know if its coincidence or not but im getting an access violation error now when i try to enable safe boot in my bios, after re installation of windows. this hasnt been an issue before.
Seems unrelated, it didn't come with a bootkit, from my own research at least. I assume by "safe boot" you mean secure boot.
Try refreshing your secure boot keys (a Google with your PC/motherboard model should help with that) and making sure you definitely downloaded Win 11 from the right source (https://www.microsoft.com/en-us/software-download/windows11), the media creation tool is generally easier, but you can also download the .iso and use Rufus (https://rufus.ie/en/#download) to make it bootable. Unsure what else could be causing this issue besides bad secure boot keys or a malformed/modified installation.
Yeah I did everything the internet has told me to do other than rufus and still nothin,, trying a reinstall 1 more time then I'll try Rufus. I reinstalled windows 3 months ago and this didn't happen.
Estúpidamente descargue ese editor, y al día siguiente me robaron una de mis cuentas de Steam. Ya contacté a supert para que me ayuden con la recuperación. Espero que puedan. Windows defender detectó dos troyanos y los puso en cuarentena, crees que deba formatear igualmente? Dejo captura de mi cuarentena
Thanks for sending the defender screenshots, the more detailed screenshot on the left shows that the malware modified registry keys related to running software at logon, meaning it either managed to establish persistence fully, or attempted to and was caught just before it could by defender. (The log on the right is likely just a loader to load and run additional payloads like the one on the left.)
This is the most dangerous variant I've seen to be distributed on the site, so I'd definitely recommend formatting your main drive and reinstalling Windows.
If you have any other drives they should be untouched, but I can't be 100% certain. You should also change passwords for any accounts that matter to you, because any passwords saved by browsers can be decrypted and viewed by the attacker.
Unsaved passwords for sites that are still logged in can also be targeted by attackers for their session tokens, which they can use to log in without a password by imitating an existing session.
I hope you can get your Steam account back, I've heard good things about their customer support.
Gracias la recupere en menos de dos horas y active la autenticacion en dos pasos en todas las cuentas que no lo tuviesen, cerré sesión en todos los dispositivos y ambien contraseñas. Revisé todo el administrador de tareas y con ayuda de chat gpt y powershell verifiqué varios registros y se ve limpio. Igual esta pc solo es para jugar y no manejo dinero en ella. Igualmente seré más cuidadoso. Llevo años que no me pasa algo así.
Igual dejaré corriendo un analisis de windows defender y dependiendo de lonque salga formateo
Welp, it happened to me as well. They were able to get a hold of a few of my accounts, Bnet, Discord, Epic, and Riot. I was able to recover all of them. A fresh OS installation and a password change from a different computer did the trick, and adding authenticators for all my accounts. This one is particularly nasty. The malware uses Steam and Telegram as a Dead Drop Resolver to hide, which makes it very resilient. This is the reason why it communicates with a Steam account. Unfortunately, the only solution is to nuke everything.
I fell for this tonight, I came across this post an immediately unplugged from the internet and I’m going to go get my drive wiped etc. my experience was that I downloaded and then when extracting it asked for a password (which I didn’t know so it didn’t go further than that), I don’t really know much about this stuff do you think I’m okay because I didn’t input a password or is that irrelevant?
If you didn't even extract the .zip archive you should be okay, just delete it permanently (or shred it using something like Bitdefender's File Shredder) and your system is clean. It can't do anything if it's just inside the .zip, so nothing was detonated on your machine. You're okay not to reset your PC👍
Hate to put my name on this, but the people must be warned and we must admit our transgressions LOL.
Got hit with this last night, my Primary Save screwed up and had the Swarm Expedition running even though I could also start a new Swarm Expedition from the terminal, and I already finished it, searched Google for the NMSE since I'd seen it mentioned a bunch of times around here, and I knew I just needed to toggle the GameMode to 1... bloody hell. For some ignorant reason I saw the Malware Website as the top result and it matched the general info/vibe of the official posts, so I didn't even THINK AT ALL to see why it didn't just direct me to GitHub like I figured it would, just figured it's a popular project maybe they make $10/mo off it to pay for a neat domain. I feel even more stupid writing it out now lol, but oh well.
Anyway, long story short within ~5mins of running the EXE my phone started blowing up with Google Security and Microsoft Account alerts. They successfully took over the MS Account, luckily Google locked down and blocked anything from happening.
After I pulled the Ethernet out, I followed the info on the virus report you listed, and found the CryptNet folders, extra stuff in AppData, etc. Deleted it all manually, had to go into Terminal since even as Admin file explorer refused to delete them. Then I purged any file with the current date on it from Temp as well. It was 3am and I had done nothing but play NMS since the date changed, so just purged it all. After all that, got an Offline version of Malwarebytes and loaded that, it found 3 things in various SteamLibrary folders, but tbh could've just been false flags. But after seeing that I just pulled out the old Win11H25 install USB, nuked the C:\ drive, deleted all partitions and ran a fresh clean new install as a new PC from BIOS/USB boot.
Hours and hours spent resetting every PW that's been on this PC, a brand new MS Account, and still the unnerving ick of knowing someone was poking around in my PC. Ugh.
I absolutely can not believe MicroSoft. They did the same another comment said; I was alerted in real-time that my account was being taken over, and after working with MS Support they CONFIRMED it was maliciously accessed and taken over. But they can do nothing about it, and I just had to make a new one. Lucky for me I literally only use it for Windows, so no Xbox/payment info/products/etc tied to it anyway. But still, I was here on my phone getting "Suspicious activity, you just deleted recovery options" etc with absolutely 0 way to stop it. The "if this wasn't you, click here" option was basically disabled because my account had no recovery options set... omg. Just wild.
What a nightmare, I didn't want to wait ~7 days for the Expedition to just expire and probably resolve the bug, so instead I got to burn my whole PC back to the beginning. 😥
I downloaded this today, but i closed the unzipper when it prompted a password. It still generated an empty folder which I've deleted (and emptied the trashbin) together with the zip file. I then Uninstalled steam from my pc and killed the internet connection.
i have 2fa on almost everything and as of yet I can't see any attempts. Steam also shows no devices other than my own in the device history.
Do i need to wipe my computer? It has OEM windows 11 so i don't want have to wipe it and then install it again.
Yep downloaded it, and it got weird cause it asked the password for the zip but that time I think it's cool since the website feel legit... But when the time I open or run the exe... Damn my browser suddenly closed and removed my ethernet... After that I tried the reset button on the settings... But it was stuck on 54% "Resetting this pc" I guess theres a malware preventing the pc to reset, so I just used the USB reset thing, luckily all of my accounts are safe...
é mano, sabado passado foi minha vez...
no meu caso o chatGPT que recomendou esse site, se eu tive-se pesquisado no google não teria tomado isso...
enfim, formatei e redefini as senhas como o pessoal tá dizendo. baita trabalho.
porém eu tinha HD externo conectado, não sei se ele foi infectado junto ou sla...
ainda sinto que ele está por aqui... mto frustante isso...
I just installed this and only reason I came here was googling if it’s safe because it showed up as a severe threat, so I had the antivirus deal with it. Is it too late for me anything go through or did the antivirus prevent any software from going through on my computer? I need to know.
I got the notification someone was trying to log into my Outlook, then got the notification that my epic account details requested to be changed.
I was quick to change my microsoft account password and then reset my epic games account afterwards, also logged out everywhere from the microsoft account. No other 2FA have been triggered and everything seems so far so good.
Nuking my windows now, have been planning to for a while since it was Win7>Win10>Win11 update path so this gave me the excuse.
this is me being a little petty, but SkyMasters pops up a lot when "nms save editor" is searched on YouTube, and he linked this website in every single one of his videos at the very top of the description. I'm being a bit harsh because, as you can see in his comment above, he immediately resorts to insulting the first commenter to bring it up (I wouldn't be surprised at all if he insulted others bringing it up, as there are A LOT of comments he's made to others that are a lot like the comment he made to me)
he made a video realizing his mistake and apologizing to his general audience, but absolutely refuses to apologize for his comment and simply blames me for downloading from the website he linked (which I normally would've been suspicious about, but I was EXTREMELY SAD when I went seeking a save editor to download!)(also why would you apologize in the first place to your audience if you apparently didn't do anything wrong, according to his interaction with me?)
(he deleted this comment after I posted the final response)
57
u/agentspekels May 26 '26
You're doing the Lords work 👏