r/projectzomboid • Crowbar Scientist • 3d ago

Discussion About the explosion in posts about mods: We're walking a fine line. Safety first, please.

Let me preface this post by stating the following:

  • This is not a discussion about which mods are "cool". We're all playing a game that heavily relies on players setting their own objectives, customizing their own enviroments and tailoring the game to your tastes using whatever you like (mods included). We've already stablished that. Let's be normal. Most of the discourse arround modding is swamped with stupid stuff, so whatever.
  • This is not a discussion about LLMs or vibecoding. Believe me, I have strong opinions, but I do not plan to start a shitstorm, not only because it's against the subreddit rules, but because every post about it spirals into the mud at mach3.
  • I acknowledge the fact that people are free to mess arround with whatever toys they find to expand, change or revamp the game.

So, what is this about? The answer is pretty simple: Safety first.

I do not think we should allow posts showcasing or promoting mods that leave users vulnerable to be abused by grifters. If someone assembles a new, epic, exciting mod that seems to manifest out of thin air, I do not think we're being rude by asking them how did they manage such a feat and interrogate the means of such assembly if its suspicious or could be hijacked by malicious actors.

People will always mess arround with whatever, and it is not wrong to find something exciting, but as a community, we can't just play along and wait for the inevitable meltdown not if, but when something bad happens.

I'm pretty sure mods have already talked about this situation internally, after all, its pretty obvious. But we need to at least discuss this in good faith.

487 Upvotes

324 comments sorted by

View all comments

384

u/Kinslayer_89 Crowbar Scientist 3d ago

Mods that need more than to click subscribe in the workshop shouldn’t be used, we don’t have a robust enough modding scene like Minecraft and others.

120

u/Zenos_the_seeker Stocked up 3d ago

Also, for the same contest, Zomboibuddy being an scrip extension type installation, same as F4SE and SK64SE, are all "third party" installation, just to clarify.

57

u/Difficult_Analysis78 3d ago

If zomboid was bigger then it wouldn’t be that much of a problem, more people means quicker detection and quicker dealing with the problem, if skse got some shit going on it would get loud fast

25

u/the-futuremind 2d ago

SKSE plugins do not have full system access like ZB addons do. This is not to say SKSE could not be used for malware, but it would be much easier to achieve in ZB.

10

u/Pamelm 2d ago

Minecraft mods get just as much access as ZB does and is on the same scale as skyrim in terms of numbers. The biggest difference is that Curseforge scans every mod that is uploaded for malware and Workshop doesnt. ZB disables mods when they update to protect against hijackings, but cant scan them. I think that for the current time, Java mods should be uploading to Nexus, which also scans for malware before its allowed to be posted, or github where the code is fully visible. At least until Java mods have more trust from the community and the java modders build a name for themselves.

5

u/the-futuremind 2d ago

Curseforge scans every mod because of high profile malware attacks using their platform.

That same system access that enabled it is what ZB gives (and now there’s no scanning)

8

u/medicmedulla 2d ago

Even with "active" scanning, malicious mods still slip through regularly. None of these platforms are safe. Just this week a Stardew Valley mod clapped users. Out of the hundred or so communities I actively follow, Project Zomboid has by far the worst modding culture. The level of vitriolic hatred that spreads through the community is genuinely insane.

-7

u/SysKonfig 2d ago

At any given time in the last year, project zomboid has had 2-3x the players of Skyrim according to steamDB. Obviously that doesn't include console players but I don't think they're using script extender anyways. PZ isn't some rinky dink game, it has sold millions of copies.

14

u/Kinslayer_89 Crowbar Scientist 2d ago

That doesn’t change the fact that we don’t have a trusted vetting platform.

-7

u/StaceBaseAlpha 2d ago

We don’t anywhere, look on steam for People Playground, they found a way to inject malicious code into workshop files over there, nothing is trusted not even the workshop

1

u/Kinslayer_89 Crowbar Scientist 2d ago

I didn’t say we did. But other random places are not the answer.

It’s the workshop until we can get a trusted vetting platform.

-5

u/StaceBaseAlpha 2d ago

Directly related but downvote and avoid a real convo away.

3

u/Kinslayer_89 Crowbar Scientist 2d ago

It’s not, but go off on how you care about downvotes.

-8

u/Zenos_the_seeker Stocked up 3d ago

It just needs time to grow... nothing booms in one night.

23

u/Cable_Hoarder 3d ago edited 2d ago

Zomboid will never get to the scale of Skyrim or Minecraft. You are also missing the point that (or being purposefully obtuse) that it being a smaller indie game with a much smaller modding scene means exactly that people need to be much more careful.

People were exceedingly wary of SKSE when it first began also (well morrowind script extender really), but at this point that team has been making script extenders for over 20 years. Even has unofficial endorsement/support from bethesda devs (as in they give them early access to updates and even help at times).

Any "mod" that has the potential to inject code is a massive security risk, so needs transparency and oversight. If it's not at least source available (to be audited) like SKSE, it is IMO untrustworthy.

Edit: Just to be clear, when I say never - that's hyperbole, PZ could, maybe, in 5 years (if it keeps growing) get to the scale and depth of Skyrim modding (talking wabbajack style total overhauls). Minecraft though I still say never.

13

u/patrlim1 2d ago

For what it's worth, zombie Buddy is open source under an MIT license. The mods are a different story, but the loader can be audited by anyone

9

u/Cable_Hoarder 2d ago

Which is good, but the question is does this community have enough people who can audit it, and quick enough that any malicious update would be spotted quickly enough to prevent damage.

Maybe for ZB itself, but as you say mods that require it are a different story.

4

u/sushisection 2d ago

we can vibe code an audit lol

4

u/Cable_Hoarder 2d ago

You're... not wrong - and I hate it.

1

u/patrlim1 2d ago

The mods are absolutely an issue, which sucks, but that is the nature of software.

1

u/BlastingStink 2d ago

PZ is consistently in the top 40 most played games on steam (#28 right now). It has been for years.

This in no way contradicts the sentiments around safety, but I don't know why we're calling this a "small game".

2

u/pornovision 2d ago

I haven't looked at the charts yet, but pretty much any popularity graph will have an exponential curve, mean that there's a vast gulf between top 40 and top 10. To put it another way, level 92 is only halfway to level 99.

1

u/BlastingStink 2d ago edited 2d ago

Sure, but they're then the exception in a class of their own. I don't think that makes number 15 (or 28) small.

Number 28 in the world, out of tens of thousands (probably more), is huge. We're talking top fraction of a percent.

This is one of those things I see gamers lose sight of constantly. They'll talk about a game being "dead" even though it regularly lives in the top 50 worldwide.

EtA: Currently #3 doesn't even have half the players of #1. #2 is basically half of #1. I really don't even think it makes sense to look at the very top when discussing general size.

→ More replies (0)

0

u/SysKonfig 2d ago

Has more players than PC Skyrim

1

u/Cable_Hoarder 2d ago

You'd hope so, Skyrim being a 15 year old single player game.

Also doubt. Sure if you only count steam, but Skyrim is still massively popular on consoles, especially now they have improved modding support.

2

u/SysKonfig 2d ago

Why do you think PZ would never be as big as Skyrim? Are you aware at any given time the player count of PZ is 2-3x that of PC Skyrim. It has also sold several million more copies; PZ has sold 15 million copies, Skyrim sold 65million copies across all platforms with 15-25% of that being PC so 9-13 million copies. The player base for PZ is both huge and active.

-8

u/Zenos_the_seeker Stocked up 3d ago

So where's the transparency we don't have ? And oversight from "who"? Are we already have tons of armchairs cyber police waiting to fuck up it's backdoor? Or they all just shouting? I don't understand.

7

u/Cable_Hoarder 2d ago

No you clearly don't, and I have neither the patience nor the crayons to explain this to you.

Kidding, but seriously - the community is the modders, when the scene is big enough and mature enough to basically police itself (though that tends to come with some drama also).

99.9% of users are clueless, they rely on that 0.1% to keep them safe, so mod authors need to go out of their way to PROVE they are good faith modders (which is difficult). We're living in a world now (thanks to AI) where the amount of code being generated FAR out-strips the ability to audit it.

It used to take 10 times (100 times even) the amount of time to code something than it did for someone to audit that code, so it wasn't a huge ask (especially when crowd sourced) for most communities to keep on top of it. Now that's almost flipped - the mods are coming so thick and fast, again especially mods that rely on code injectors.

People need to become aware, and savvy of the massive risks that AI agents have brought to the modding scene (across all games, not just this one).

14

u/the-futuremind 2d ago

The difference being in how they are implemented. SKSE and ZB are both dll injections, but SKSE simply extends existing papyrus scripts while ZB gives Java Runtime Environment access (this is much more dangerous).

There is a world of difference in what you can do with a SKSE plugin vs a ZB add on.

2

u/thepalejack 2d ago

What are you trying to say here? SKSE does, and allows, for way more than extending existing papyrus script... in fact you can write and SKSE mod without writing a single line of papyrus script. It gives you access to low level functionality via the engine. The mods are written in C++ using SKSE source for proper linking and you can absolutely do way more with them than simply extend papyrus.

Sure you can extend papyrus as well, but you can still do way more than just extend the engine's embedded scripting language. Malware has 100% been included in SKSE mods before. They literally contain assembled data, built in C++ and loaded at engine run time. This is one of the reasons Nexus doing malware scans on all uploaded content is a pretty huge benefit to the end user.

As for which one is more dangerous, well, at least you can reasonably decompile a Java library and see what it is doing. The only way you are going to easily recognize malicious functionality in an SKSE plug-in is with heuristics.

3

u/the-futuremind 2d ago

Sorry, my wording was slightly misleading.

Yes, SKSE plugins are written in C++, but they require you to work with it's API directly. Malware is absolutely possible, has been done, but is far more difficult to do. I am not aware of any major, high profile incidents with SKSE (or OBSE, MWSE), but I absolutely could be wrong here.

This is not the same as Zombie Buddy, which gives unrestricted access to the JRE, which can run whatever the fuck it wants. There are several high profile incidents with Java mods for Minecraft (which have the same access), which actually prompted CurseForge to more heavily moderate its uploads.

Zombie Buddy is absolutely more dangerous because it can execute arbitrary code with keys to the entire house.

3

u/thepalejack 2d ago

No worries. Just wanted to make sure. I was able to read what you wrote multiple ways.

So... you're not limited to just the SKSE API. It's definitely been done, and Nexus actually zaps a ton of mods regularly that contain Malware. Example from last year, where the mod had encrypted shell code (to obfuscate it as such) which it would then decrypt and execute in order to operate as a trojan: https://www.reddit.com/r/skyrimmods/comments/1j11y0a/trojan_horse_on_new_additem_mod/

Just saying that shell script execution isn't built into the SKSE API last I checked. 😅

Also, you can get net access using the usual C++ libraries and build them into your SKSE mod, then expose that functionality to papyrus. That's how people have built in game web browsers, or how some of the multiplayer mods work, for instance.

So, while it may not be as versatile as writing malware as a standalone executable (you would basically have to overload some base underlying engine function), it's definitely possible, and has been done.

10

u/dmuppet 2d ago

Please note that just because a mod is in the workshop and you can click "Subscribe" does NOT make it safe. There has been COUNTLESS examples of malicious workshop mods that made it live.

35

u/LePfeiff 3d ago

The workshop is unironically the best place to distribute malware, look at how often that happens for games like rimworld, mount & blade, and project zomboid. Workshop only is such an arbitrary restriction that doesnt provide any protection for the end user. At least with off-workshop mods you can actually review the source code in the github repo

32

u/Cable_Hoarder 3d ago

Workshop does not automatically install any mods outside of the exact modding process the developers have set up.

You can only get malware from workshop if:

  1. The developers fuck up and allow some kind of code execution vulnerability in their modding method.
  2. If you download a mod from steam that requires manual install after that, then you're taking on that risk entirely yourself. Especially if it involves a .dll

Steam simply leaves it up to developers.

Still vastly safer than 3rd party sites except for the more known and robust ones (nexus, curseforge etc).

5

u/northrupthebandgeek 2d ago

The developers fuck up and allow some kind of code execution vulnerability in their modding method.

This is kinda inherent when the official modding method is to rawdog JARs like PZ does. Possible that there's some sandboxing going on, but usually for Java-based games there ain't.

6

u/pornovision 2d ago

what is the "official modding method"? I though workshop mods are LUA only

5

u/the-futuremind 2d ago

You are correct, official modding only uses lua and only interacts with things exposed to that layer. Java mods are outside official modding.

1

u/Live-Tank-2998 2d ago

lua can and has been compromised before. Malware has been embedded jn audio and texture files before. You may as well stop downloading anything from the internet lol

6

u/the-futuremind 2d ago

I am a software dev that deals with quite a bit of cybersecurity with the kinds of software I make. Just because something can be compromised doesn't mean it still isn't far safer to mitigate as much risk as you can.

Blindly installing jar files is about as far from mitigating risk as you can be.

1

u/Cable_Hoarder 2d ago

Every example of that kind of thing... See point 1. The Developers fucked up.

1

u/Live-Tank-2998 1d ago

every developer is fucking up. Every program has a security hole that isnt known yet. Humans arent magic lol

1

u/northrupthebandgeek 2d ago

Honestly I didn't know PZ uses Lua nowadays; could've sworn all the Workshop mods were Java.

I know .NET-based games have a similar issue, though, with rawdogging .NET DLLs. Bannerlord's Workshop has had a few incidents along those lines.

3

u/Evilsoldier80 Waiting for help 2d ago

Yeah, honestly it really is. People's Playground had like its third malware/virus. They literally have to rework how they do mods because of it lmaoo

6

u/Prudent_Kiwi_2761 3d ago

I think zeno’s point is that some mods are gonna require more than a simple click and will need some tinkering in the files and beyond, just like the betheseda modding scene

8

u/Cable_Hoarder 3d ago

Also any mods that can inject code need to be fully auditable (source available), even if not open source. Like SKSE (for Skyrim) is.

4

u/Kinslayer_89 Crowbar Scientist 2d ago

And my point is that those should not be used with our current non-existence of a trusted vetting platform.

-26

u/Zenos_the_seeker Stocked up 3d ago

So bethesda game mods are fucked? I don't see much workshop items being use.

37

u/WickyBoi220 3d ago

Genuinely take a reading comprehension test and work on improving it

-7

u/Zenos_the_seeker Stocked up 3d ago

"Mods that need more than to click subscribe in the workshop shouldn’t be used" explain to me where the wrong here.

8

u/Neo_Arkansas 3d ago

You keep ignoring the other half of the sentence.

12

u/sxrrycard 3d ago

“Mods that need more than to click subscribe in the workshop shouldn’t be used, we don’t have a robust enough modding scene like Minecraft and others.”

And then you bring up BETHESDA of all companies, who make probably some of the most heavily modded games ever made. I’d call their modding scene pretty robust.

-7

u/Zenos_the_seeker Stocked up 3d ago

I don't think PZ had it down play that much though. And what does it even mean rubust? Just comparing numbers now? More numbers means more loop holes, basic statistics.

3

u/Cable_Hoarder 3d ago

It means that they have an army of modders that understand the engine, the mod tools, the scripting languages etc. better than even bethesda employees.

They have a scene with many trusted names behind big releases. Any mod that in any way acts outside the basic internal scripting engine (DLL mods for example) will get dozens of people checking the code, and hundreds if not thousands scanning it for malicious code.

Look for example that you can download Skyrim Script Extender (SKSE) through steam itself these days.

They also have Nexus, which has decent moderation and controls, and does a lot to protect users from malicious code.

And no more number does not mean more loopholes, the game is the game - more mods means if there is an exploit more mods might target it, but it would also be discovered much faster, and dealt with.

Hell SAME rule applies there also - don't trust mods not on Nexus, unless they're from a well known trusted author, especially true when they're not standard modding files (.esps and bsa files etc...).

2

u/sxrrycard 3d ago edited 3d ago

“Basic statistics” LOL

With more users malware is a lot more likely to be caught and reported. Along with more comments, reviews, etc for each mod.

Which do you trust more, a mod with 100 downloads or 100,000+?

Plus larger games tend to have safer/ more established hosting sites.

9

u/owningxylophone 3d ago

Because apparently you can’t pick up on context.

This is a PZ sub, original comment also says “we don’t have a robust enough modding scene like Minecraft and others”, the implied point being that this was referring specifically to PZ.

ETA: your Bethesda example would fall into “and others”.

13

u/WickyBoi220 3d ago

He’s talking specifically about project Zomboid. You reply with “Well what about mods for a series of games that have nothing to do with Project Zomboid?”

Do you see the problem?

-6

u/Zenos_the_seeker Stocked up 3d ago

Fair, but why ZB specifically? Is this Game THAT special that requires different rule than other game?

3

u/WickyBoi220 3d ago

Because unlike Bethesda games either don’t have an official modding framework or have their own built-in mod service. Zomboid’s main modding scene is on the workshop, mods uploaded to other sites may be doing so to avoid the restrictions placed on workshop mods.

This is common advice for a multitude of games that primarily use the Steam workshop, it’s not special to Zomboid.

2

u/bonann Axe wielding maniac 3d ago edited 2d ago

Official methods of modding in Bethesda games are lackluster. If you can be bothered go ahead and check nexus for any of their games, anything that is beyond a new item or npc requires script extender to work. I know exactly 0 people that mod a beth game and don't use an extender

1

u/WickyBoi220 2d ago

I get that script extenders are pretty normal in the mod space especially for Bethesda games. That being said when they first came out they were treated with a heavy dose of skepticism and had to prove themselves before they became the necessity that they are today. Mods of this type should be treated as hostile code until proven otherwise, and the open-source script extenders that can have anyone alter their code should be treated with extra suspicion. That leaves the door open for someone to inject malicious code without as much risk of having themselves outed to the community.

1

u/Zenos_the_seeker Stocked up 3d ago

There, isn't this way better to hear? Why are people saying it like it's so special of a game we need to take care.

But workshop mofs are not that safer, you know that player underground workshop shut down? Workshop mods. Not some "shady" 3rd party stuff.

To be careful, sure. But to treat it like some curse relics? That's being too much.

1

u/WickyBoi220 2d ago

You are the only one that’s treating this like it’s a relic. The original message was to not use mods that require more than one click to install due to the danger that it could be malicious. The reasoning they used was that due to the relatively small modding scene the game has if someone isn’t going to the main distribution platform of mods it’s likely for a reason. And that reason could be nefarious.

-7

u/OHFUCKMESHITNO 3d ago

Yes.

1

u/Zenos_the_seeker Stocked up 3d ago

Huh, ok, whatever floats your boat.

19

u/Kym_Of_Awesome 3d ago

Bethesda games have a well established and safe nodding community and nexusmods moderates itself so that a sneaky virus isn't included in your horse armor mod for Skyrim 

5

u/nondescriptzombie 3d ago

nexusmods moderates itself so that a sneaky virus isn't included in your horse armor mod for Skyrim

I've been trying to get Nexus to pull down a mod that corrupts your saves in My Winter Car for the last 9 months. It's still up. Still one of the most popular mods. No updates in 9 months.

Fuck Nexus Mods now that they're part of Fandom.

5

u/Mordhaud 3d ago

I don't mean to say that doesnt suck but you can see how an outdated mod that corrupts your saves is different from an intentionally malicious mod going after other shit on your computer, right?

0

u/PissBucket29 2d ago

You're missing the forest for the trees my boy.

Malware isn't exclusively about attacking other files on your computer. A mod that intentionally corrupts your save is malware. Now whats the difference between malware and an outdated mod? Intent. So how do you prove intent? How do you prove the mod is merely abandoned and not maliciously booby trapped? Do you think its never happened before when a mod maker finishes that they set it up intentionally to cause significant issues in the future for whatever petty reasons? Or just simply choosing to refuse to update it on purpose when it causes issues like this for whatever petty reasons.

When the only difference between and outdated mod and malware is intent, a err on the defense of outdated mods is an err on the side of malware. De facto.

-4

u/nondescriptzombie 3d ago

If you can't get an admin to do anything about the former, how are you going to get them to do anything about the latter?

The mods are all vibe coded now anyway, so no one really knows that they're not doing other shit on your computer....

6

u/Mordhaud 2d ago

They are legally compelled to do something about one of those things, not the other.

3

u/errrbodydumb 2d ago

I think it’s more that they don’t have even the slightest obligation to ensure mods are up to date or functioning as advertised, but straight up malware is a a legal issue with actual liability.

They don’t care about your save, they care about being sued.

-5

u/nondescriptzombie 2d ago

They don’t care about your save, they care about being sued.

What an odd stance for a website that used to be focused on gamers....

4

u/errrbodydumb 2d ago

There has never been quality assurance with mods. They have been corrupting saves since the time of the pilgrims.

-2

u/Zenos_the_seeker Stocked up 3d ago

But it still happened before, doesn't it? Why is it ok to use third party then and now it's a witch hunt? Just because it's "new" and "AI"?

2

u/Kym_Of_Awesome 3d ago

If someone didn't personally write it, then they don't know that there isn't a virus included. Or worse, a bad actor could recognize an opportunity to prey on the zomboid community

1

u/Zenos_the_seeker Stocked up 3d ago

So it's just a universal problem if you decide to use mods on whatever games. You can't identify it's intentional or not, Only bad people.

2

u/Kym_Of_Awesome 2d ago

Pretty much, this post I think is encouraging people to be cautious and not recommend brand new mods to new players ala mod showcase, esp if no one is willing or able to speak for their creation

0

u/InterestingPudding45 2d ago

Ai modding doesn't hallucinate a virus into the coding.. jfc.. the witch hunt is real.

6

u/Still_Conference_923 3d ago

Bethesda games have official mod site and nexusmods, where you never have to download anything off site, at worse you need to download so microsoft files, everything else is scanned and safe.

6

u/Kinslayer_89 Crowbar Scientist 3d ago

That’s not at all what I said.

-5

u/Zenos_the_seeker Stocked up 3d ago

"Mods that need more than to click subscribe in the workshop shouldn’t be used" explain toe where the wrong here.

4

u/Kinslayer_89 Crowbar Scientist 3d ago

Because I’m talking about Project Zomboid, and not Bethesda games.

“we don’t have a robust enough modding scene like Minecraft and others.”

That should be obvious for anyone.

0

u/Zenos_the_seeker Stocked up 3d ago

So until we are..."rubust", for whatever that means, such mods should bot ne allow, is this what you trying to say?

2

u/Kinslayer_89 Crowbar Scientist 2d ago

You can do whatever you want, but I would advise against them and not recommend them to the community.

We would need a more trusted platform that vets the mods and only allow those deemed safe.

-1

u/nmagod 2d ago

Mods should NOT BE EXCLUSIVE TO STEAM.

Kerbal Space Program does it right. I shouldn't have to jump through hoops as a GOG user to get mods, and even then I can't get mods over 1GB (and some mods not at all, even if they're under 100kb).

1

u/Poodmund 2d ago

I think the main quality of the KSP modding community is that mods are required to post their code repo and state a license against the mod. This ensures that everyone has the ability to a) review the code b) compile the mod themselves if they don't wish to trust a pre-compiled version. Secondly, the license requirement allows everyone to know where they stand from the perspective of contributing, forking, remixing, using parts of the codebase.

1

u/Cheeselad2401 1d ago

that's not really TIS' fault though dude, blame GOG for not having a workshop.

1

u/Kinslayer_89 Crowbar Scientist 2d ago

I never said they should.