I have been playing BeamNG.Drive since 2018. I have enjoyed every second of my over 1,600 hours of playtime. Over my years, I looked towards the in game repository and forums for my mods. I also use other sites, but what we are talking about would not bother me if it happened on other sites because it is a risk I'm willing to take. But there should never ever be a possibility that a mod that I got from the in game repo could be compromised in any way. I expect to be able to download mods on here without worry of getting my information stolen. This is unacceptable and something needs to be done to prevent this because whatever is being done now is not enough. There is no reason that someones antivirus could catch this but whatever is used to scan mods could not. This is a severe privacy concern and I recommend people stop using the repo and disallow this game from the internet until there is a proven fix. https://lemonyte.com/blog/beamng-malwareh
The vulnerability was but not the ability for malware to pass through scans as far as I know. There is also no reason a mod should be able to access the internet in any way.
i think they are in the process of getting this sorted out as the amount of mods allowed on to the repo the last couple days has been alot less too me that means they might have removed the person that let that through from mod reviews or they are now doing a much more thorough check
I'm really f-ing angry right now. I was one of the 3500 people who downloaded the version of american road with the malware. This was a month ago. I dont blame Beamng that the mod got uploaded. Mistakes happen. Things slip through. Unsandboxed 6 year old chromium is a bit more annoying. whatever BUT! Why did i first hear about it in a blog post which i came across by pure chance a whole month after the incident? This is just unacceptable. Where was the steam announcment? Where was the devblog post? Where was the ingame notification? Discord @everyone? Anything?! THERE ISNT EVEN ANY INFO ON THE MODPAGE ITSELF AS OF RIGHT NOW. WTF! Love you guys(devs) but this was handled as bad as it gets. Like leaving me and 3500 others just uninformed is so bad.
I formerly thought the malware was false. It is not. Stenyak confirmed the American Road malware update was real but was removed a couple days ago
Agreed. That is what I was going to say but I accidentally posted before I was ready. They did not handle this well at all. And did not have the correct security measures to prevent it. Dhid you notice any of your accounts being hacked?
lmao, now they just removed american road from the forums and the repository. i thought the malware was removed on april the 24th? tbh i dont even want to imply anything. but what am i supposed to take away from this? from the outside this looks like beamng is just fumbling and doing damage control the wrong way. there might be a super innocent explanation for this? BUT HOW WOULD I KNOW IF THERE IS STILL NO OFFICAL STATEMENT?! sorry, but i'm done. hard to be excited about a security risk and by that i mean the company and its policy. i'm seriously disappointed. this game was a constant for me the last 10 years. but i dont feel like a have any trust left. get your shit together beamng
What I also find unacceptable is that the forum thread was deleted now. It had important infos on this whole mess that is just gone now. I was one of the last ones who posted a question there, and I really want an answer to it... (basically, I want to know if I missed the malicious version by only a few hours before updating to BeamNG version 0.35 ... I need to know at what time (taking into account the time zone) the malicious version of the mod was uploaded to the repo, the date isn't enough...). I hope the reason the mod is now completely gone doesn't mean there is still malware in it... EDIT: Nevermind, the American Road thread (and the mod itself) is online again.
Ah, it seems the thread was deleted by accident, sorry about that! Regarding that article, it contained outdated information. Please check this message I wrote days ago for a better overview of the situation: https://www.beamng.com/threads/american-road.50374/page-39#post-1843495
I don't know what that Slapchopp guy was talking about, but I was actually one of the first to publicly inform people that there was probably a virus in American Roads. Even most of my fans didn't believe me at first that something like that was possible, but considering that the developers themselves deleted the map and then re-uploaded it back to the forum, it slowly started to dawn on everyone. Otherwise, you're right, I'm really not a security expert by any means.