Skip to main content

Indie game storeFree gamesFun gamesHorror games
Game developmentAssetsComics
SalesBundles
Jobs
TagsGame Engines

PSA: Beware the "try my game" scam Sticky

A topic by leafo created Sep 22, 2021 Views: 145,899 Replies: 155
Viewing posts 1 to 20 of 128 · Next page · Last page
Admin (18 edits) (+45)

Malware is being distributed on Discord and other platforms by hackers who ask you to “try their game” by downloading an unsafe executable off the internet. This malware steals your Discord account, hacks your browser, steals payment information, and more. These hackers are using any file hosting sites they can, including itch.io, to attempt to distribute their viruses.

  • If you receive a DM from someone you don’t fully trust asking you to download or test their game, DO NOT DOWNLOAD
    • Even if it’s someone you DO know, if their behavior is strange then their account may have gotten hacked through this scam. Do not download any executables they try to send you
  • On itch.io, it is safe to view the page, but do not download any untrusted software
  • Games that run in your browser are sandboxed by your browser and pose no risk of infecting your computer
  • If you see a zip file that is “password protected” DO NOT DOWNLOAD. Scammers encrypt their zip files with passwords so file hosts can’t run malware scans on the contents. Report this page
  • On itch.io, you can report a page from the link located on the bottom of the page.

Here’s the most common example we’ve seen:

  • Unsuspecting user has the Discord app installed on their Windows computer
  • They receive a DM from someone they may or may not know (it may be someone that hasn’t spoken to you in a long time, or someone from a mutual server)
  • The hacker asks you to test a game they’re working on and provide an itch.io or other link to download the software
  • The software is a program that reads specific files on your computer to steal your Discord API token, your Browser’s cookies, any other sensitive data.
    • They may also delete these files after stealing them, so you effectively get “logged out” from everything after the malware rune
  • In the example of Discord: The stolen API token gives full access to your Discord account with no restriction on where or how it can be used
  • The scammer uses this token to:
    • Steal your account from you (change password, email)
    • Use stored payment information to spend thousands of dollars on Discord Nitro/Server boosts
    • They may message from your account to your friends list/servers with the same or similar message asking others to download the file

itch.io is a self publishing platform open to all, which means anyone can publish a page on our platform at any time.[1] Although we have many automated checks to block or suspend users if suspicious activity is detected (including human review in many cases), not all scans and systems are perfect. We’re releasing this notice along with a few other changes to our platform to educate and help prevent this kind of attack.

itch.io at its core is a public file hosting service. Treat any page you encounter with suspicion if you are unable to vet the creators in any way. If you are concerned about the security of your computer and don’t trust any malware scanners you have on your computer then we recommend you stick to HTML5 games, as they are sandboxed by default. We also provide a Sandboxed mode in our app, but it’s difficult to guarantee security for downloaded software. Your browser is likely the safest sandbox your computer already has.

Note: We will not reveal the specifics of how we handle malware uploads or other illegal activity as it’s very likely the scammers are reading this very thread.

Thanks

[1] Publishing can represent a broad range of states on our platform, from being indexed on our search and browse pages to just having a URL that can be shared. In this case we are referring to just creating a URL you can visit directly by link. In no instances have these pages been promoted by us on any part of our site like the homepage or browse pages

More information about the scam

(+6)

Hello 

Same thing happened to me 2 days ago from this site . A person named snowwy DMed me that if I advertise his game he will pay me and he gave the link to test bugs . As soon as I opened it logged me out from the discord and my account hacked

the link is https://coolcoder1.itch.io/stick-fight

Please remove this file from this site

Thank you

Deleted 133 days ago
(+5)

Hi, to anyone is coming across this, a group of individuals have come together hoping to reverse engineer and disable these scams as soon as new ones come up (they phone home using discord webhooks which can be disabled remotely). We are cataloging our findings on a public wiki. If you have come into contact with a compromised account or have been sent malware, please forward it to us so we can hopefully break it open and render that build inert.

You can learn more or help stop these here: ⭷ https://security.shulker.net/wiki/Main_Page

Shoutouts to: GlitchyPSI, PhleBuster, Vixus, Kibbles, and everyone else helping out!

Admin

Just giving you a heads-up but it looks like your wiki is full of spammers.

(+1)

because my game super slosyto game can not be downloaded the game has more than 3 months in review everything simply because I live in Venezuela and I have no discord please unblock the game please

That URL doesn't exist.

(+2)

Does this affect Linux (Ubuntu) computers?

Admin(+3)

The malware we’ve seen is only for Windows computers, but many of the warnings I wrote about apply to all downloaded software.

(1 edit) (+1)

https://mandagame.itch.io/manda 

edit; thanks for deleting that one, these guys are horrible

https://helpercat.itch.io/helpercat is one of those, please remove it

https://helpercats.itch.io/helper-cat Please remove this file from this site

Thank you :DDD

(+1)

here's another one

https://mercydevs.itch.io/

Got sent to me on discord. The game is in JS and nothing detected it as a virus - I used BitDefender Total Security and VirusTotal (the site)

Admin (1 edit) (+4)

Please report the game page as well, it helps our team quickly respond. If you reply to this thread here only I will get notified. Thanks

(+1)

Hey Leafo, can you help me someone stole my game called Not All There and reuploaded it here https://okpti.itch.io/not-all-there

(+1)

What about if I didn't receive the link through Discord, like this HelperCat game that some people are reporting appeared in my feed as any other. So how can we check this? Running an antivirus doesn't help in all cases

(+5)

Hello, I have created a game and I use discord a lot, I would like to know if there is a way to make a kind of verification so that there is no more this image when I transmit my game via discord.

 

(+1)

I would really like to know this too, I'll do whatever they ask.

Yeah, no solution?

In the end it disappeared by itself after a while

Really...Why there are so many "games"...that they are virus...?

(+1)

Hey, I also created a game - it's not even downloadable since you can only play it in the browser. Is there any way to remove this warning? I want to show my friends, but now they're all too sketched out by the website warning to even touch it. Really disappointing. 

Me too it's really frustrating

Yes it is /:

(1 edit)

I found another scammer one just today https://evadevs.itch.io/cyberika

(+5)

This is such a shame, now people won’t have trust for actual developers  :(

但我们别无他法,无法与他们抗争。

I got scammed another way via a hacked friends account and a suspicious website but I got refunded

https://trabusvr.itch.io/trabus

https://zinetragames.itch.io/tribus-gamebynetra Yea, this one got my boy. My innocent boy.

Viewing posts 1 to 20 of 128 · Next page · Last page