This man has made over 200k+ Robux by making this malicious script that inserts a (fake?) 50R$ admin command into infected games

All I’m seeing is this e.e

It has something to do with ThirdPartySales but the thing is I have it turned off so how is that even possible that they have a Marketplace product in my game?

1 Like

A method I use is by searching Welding, Fix, Weld or Debounce into explorer and delete any script with those names, they normally will appear “empty” or saying something about “this script is from ROBLOX” (which is not true) also any unnamed scripts could be the backdoor.

Can’t confirm.

The module seems to have been obfuscated with Luraph.
I am not sure of how to dump Luraph’s constants but what I could find is that it also requires this module

1 Like

I found Debounce, but the script is blank, nothing inside the script. What do I do with it?

Are you absolutely sure?

Because a lot of these scripts just indent soooo much that the script has a horizontal scrollbar.

1 Like

Just delete the entire script.

Yes I’m absolutely sure because the script has no scroll bars it’s literally a blank script named Debounce inside a part that I have no idea how it got there. Also I can’t revert to an old version because I have no clue how long it’s been like this until I finally tested the game for a while, this is what my version history looks like:

1 Like

Did you find anything? I tried to search what you wrote and it showed nothing for me…

No its not a product Id, it a module script Id, why not just delete that script.

How do I find that module script id though?

@sjr04 linked it in his post above.

I got the model, it looks like this


How do I decompile that

1 Like

Also I did delete the script and nothing happened, the marketplace admin pop up still comes

Did you delete the other one?The search results that you posted found two.

Yes that was the same script with the one I deleted

I would try to print what it says in there.

This may be an off-topic question but is this allowed or not on Roblox? Are they allowed to insert a script like this into an infected asset.

EDIT: It’s not like I want to do it myself, just curious.

It shouldn’t be, I still can’t get rid of it. I researched and saw that ThirdPartySales is a broken feature…

1 Like

it might be bytecoded? like

\13\123\123\123\123\13

try searching