Malicious code is able to show UI over the purchase prompt, and trick users into purchasing items

Unfortunately this scam is built on scam games made by scammers, I’ve never seen cases of this happening on pre-existing games as it would need modification of coregui scripts which can’t be done by scripts, however disabling Allow Third Party Sales and Allow Third Party Teleports is useful advice as there are still “Loading…” scripts which can attack games, mostly in hijacked admin scripts and insert backdoors and track the game with the backdoors using discord webhooks. I covered how they worked in my blog called RBXDevnotofficial. Link to article