- May 30, 2021
- 36
- 44
case will be closed next month ig, we'll see if people start complaining about spyware or some other thingsLet's have a look at this message in particular.
Yes, it has obfuscated JavaScript files and AES-encrypted JSON files. The DRM was inside the obfuscated JS and called from the JSON files. Just because the files are "normal", doesn't mean they can't be malicious. Due to the game being run in NW.js, it is able to easily interact with files outside of the game (not to mention one of the plugins used in the game writes to and calls a Visual BASIC script).
Anti-virus websites like Virustotal can't detect everything, mainly as they are limited to just opening the game in a sandbox and seeing what it does. Anything that happens later cannot be reliably detected.
See also the Renpy games that had malicious code added to one of the python scripts that wasn't detected by AVs (yet they continuously report the main Renpy exe as a false positive).
edit: whoever is reading this and is planning to download this game, check the sourcecode if you can
Last edited: