Virus in plugins

As someone who actively uses these plugins (from their original creators), it sickens me that someone is trying to exploit games by creating fakes. I recommend these plugins to new developers and if they installed the fake one, they will think I am promoting exploiter material. I sincerely hope Roblox swiftly takes down those fake plugins, removes the group that impersonates plugin creators, and bans the player behind it. Furthermore I hope they remove the ability to have the @ symbol in group names to prevent this from happening further.

1 Like

Even the “Load Character Pro” plugin?

All of those plugins posted above have the creator as a group and the name is impersonating the real plugin creator using the @ tag.

2 Likes

Its by a person making them self look as the original creator through groups.

1 Like

Oh, wow. I didn’t even realize it could look that real.

Yeah I almost downloaded one before I looked up the name on here and found this.

1 Like

Yea. An oversight for sure when Roblox added the DisplayName feature.

Popular plugin creators probably know about these things since their plugins get copied like this all the time. It’s one of the reasons Roblox made plugins pending approval. It’s just I guess somehow these slipped through?

Edit: these did not slip through, as they do not appear in the Toolbox in studio. Only install plugins from the Toolbox to be safe, and not from the website.

I guarantee it slips through all the time because ROBLOX has to check high quantities of items every time a new piece of clothing, game, decal, etc. is waiting to be approved when it is uploading.

Don’t use the website’s plugin marketplace unless you’re absolutely certain that you are installing a plugin from a trustworthy source. At present it’s an unregulated wild west.

Plugin permissions were a step in the right direction, but I think more could be done to provide clarity for what these plugins are trying to do.

11 Likes

these plugins can be 100% fatal to your game. They open up backdoors that exploiters can use to hijack your games servers, they can create false/hidden scripts to put up stuff and more stuff that absolutely screw up your game.

It’s sometimes not over when you delete these. These plugins save the scripts into your game sometimes like viruses. I remember deleting a free model and a virus’s script was still in my game.

Remember, look out for any suspicious detail on the plugin to ensure that your game will be safe from anything.

Do you have to search through the explorer and make sure there is no scripts that aren’t supposed to be there to get rid of them completely or will ctrl+a and backspace get them?

Here’s one tip. Name all your scripts or just put kiahd on final of the name then
after you’re done go to the explorer and search for scripts.

4 Likes

I always try to find if there are comments or how many downloads, favourites and likes/dislikes it does have,

i then try to find some link of youtube if someone tried the plugin so i know if it’s verified.

2 Likes

The script explorer will be some help though, although it might not find every single one of those damn things, it still can do some damage. Theres no way to completely get rid of all of them 100% of the time because they find a way to duplicate. Try just going back one update and search scripts.

1 Like

You could use the roblox Replace all in every script
feature, search 0x19F996F0A then replace it with something like 1

Oh boy there’s more
image

and this lol


@Xenoqe liked all of the posts calling him out for his crimes.

4 Likes

That’s not really hacking. Just a serverside backdoor that grants users some powers in infected games and can be really abusable where can reach game deletion or maybe leading his account to get moderation.

1 Like

image
It’s gotten worse, i know AlreadyPro is for a fake Character Inserter.

2 Likes

Someone higher than our level need do somehting.

1 Like

First of all, no, they don’t hack accounts as far I know. Studio cannot give out any player’s information including the client user (ex. password, .ROBLOSECURITY cookie, etc).

They are 'backdoor’s, and they allow exploiters have serversided access to the backdoored games. The owners do make money from it, with BTC, Paypal, Robux and more.

:warning: Please avoid installing plugins that have virus(ses), you should check the plugin or model owner first before you install/insert ANYTHING to studio. :warning: