Patching a Zero Day Exploit

On April 7th, we received reports from multiple users regarding a mod that was allegedly generating malicious code when run. We immediately investigated the mod in question, which contained heavily obfuscated code, and confirmed that it was creating malicious files outside of the Project Zomboid directory.Further investigation revealed that the same user had uploaded a total of 14 mods, all containing the same exploit. These mods had been installed on between 500 and 2200 devices. The user has since been banned, and all affected mods have been removed from the Steam Workshop.At this time, the full scope and behavior of the malicious files have not been fully determined. However, because these mods were capable of creating files outside the game directory, we strongly recommend that anyone who downloaded them take appropriate security measures to ensure their system is safe. Simply uninstalling the mods is not sufficient.Affected Mods- Risk of Rain 2 OST (True MoooZIC)- Risk of Rain 1 OST (True MoooZIC)- NieR: Automata OST (True MoooZIC)- Katana ZERO OST (True MoooZIC)- Persona 5 OST (True MoooZIC)- Jujutsu Kaisen S1 OST (True MoooZIC)- Hotline Miami 2: Wrong Number OST (True MoooZIC)- Hotline Miami OST (True MoooZIC)- Silent Hill OST (True MoooZIC)- Cowboy Bebop OST (True MoooZIC)- Metal Gear Rising: Revengeance Vocal Tracks (True MoooZIC)- Classic Roblox Music (True MoooZIC)- DELTARUNE Ch3+4 Music (True MoooZIC)- Minecraft Alpha+Beta OST (True MoooZIC)Additional InformationThis exploit only affected Build 42 branches. Build 41 was not vulnerable to this specific issue.The security updates released for Build 41 today address a separate vulnerability identified during an internal audit. At this time, we have found no evidence that this separate vulnerability has been exploited.As with previous security fixes, we have updated the outdatedunstable branch to match the unstable branch to avoid leaving a known vulnerability accessible. Going forward, outdatedunstable will continue to lag one content update behind unstable.

Apr 8, 2026 - 23:57
 0
Patching a Zero Day Exploit
On April 7th, we received reports from multiple users regarding a mod that was allegedly generating malicious code when run. We immediately investigated the mod in question, which contained heavily obfuscated code, and confirmed that it was creating malicious files outside of the Project Zomboid directory.

Further investigation revealed that the same user had uploaded a total of 14 mods, all containing the same exploit. These mods had been installed on between 500 and 2200 devices. The user has since been banned, and all affected mods have been removed from the Steam Workshop.

At this time, the full scope and behavior of the malicious files have not been fully determined. However, because these mods were capable of creating files outside the game directory, we strongly recommend that anyone who downloaded them take appropriate security measures to ensure their system is safe. Simply uninstalling the mods is not sufficient.

Affected Mods

- Risk of Rain 2 OST (True MoooZIC)
- Risk of Rain 1 OST (True MoooZIC)
- NieR: Automata OST (True MoooZIC)
- Katana ZERO OST (True MoooZIC)
- Persona 5 OST (True MoooZIC)
- Jujutsu Kaisen S1 OST (True MoooZIC)
- Hotline Miami 2: Wrong Number OST (True MoooZIC)
- Hotline Miami OST (True MoooZIC)
- Silent Hill OST (True MoooZIC)
- Cowboy Bebop OST (True MoooZIC)
- Metal Gear Rising: Revengeance Vocal Tracks (True MoooZIC)
- Classic Roblox Music (True MoooZIC)
- DELTARUNE Ch3+4 Music (True MoooZIC)
- Minecraft Alpha+Beta OST (True MoooZIC)

Additional Information

This exploit only affected Build 42 branches. Build 41 was not vulnerable to this specific issue.

The security updates released for Build 41 today address a separate vulnerability identified during an internal audit. At this time, we have found no evidence that this separate vulnerability has been exploited.

As with previous security fixes, we have updated the outdatedunstable branch to match the unstable branch to avoid leaving a known vulnerability accessible. Going forward, outdatedunstable will continue to lag one content update behind unstable.

What's Your Reaction?

like

dislike

love

funny

angry

sad

wow

XINKER - Business and Income Tips Explore XINKER, the ultimate platform for mastering business strategies, discovering passive income opportunities, and learning success principles. Join a community of thinkers dedicated to achieving financial freedom and entrepreneurial excellence.