On April 7th, we received reports from multiple users regarding a mod that was allegedly generating malicious code when run. We immediately investigated the mod in question, which contained heavily obfuscated code, and confirmed that it was creating malicious files outside of the Project Zomboid directory.Further investigation revealed that the same user had uploaded a total of 14 mods, all containing the same exploit. These mods had been installed on between 500 and 2200 devices. The user has since been banned, and all affected mods have been removed from the Steam Workshop.At this time, the full scope and behavior of the malicious files have not been fully determined. However, because these mods were capable of creating files outside the game directory, we strongly recommend that anyone who downloaded them take appropriate security measures to ensure their system is safe. Simply uninstalling the mods is not sufficient.Affected Mods- Risk of Rain 2 OST (True MoooZIC)Workshop ID: 3681934105 – Mod ID: RiskOfRain2Music- Risk of Rain 1 OST (True MoooZIC)Workshop ID: 3681810963 – Mod ID: RiskOfRain1Music- NieR: Automata OST (True MoooZIC)Workshop ID: 3681765529 – Mod ID: NierAutomataMusic- Katana ZERO OST (True MoooZIC)Workshop ID: 3681764942 – Mod ID: KatanaZeroMusic- Persona 5 OST (True MoooZIC)Workshop ID: 3681756112 – Mod ID: Persona5Music- Jujutsu Kaisen S1 OST (True MoooZIC)Workshop ID: 3681755051 – Mod ID: JujutsuKaisenMusic- Hotline Miami 2: Wrong Number OST (True MoooZIC)Workshop ID: 3681719339 – Mod ID: HotlineMiami2Music- Hotline Miami OST (True MoooZIC)Workshop ID: 3681718339 – Mod ID: HotlineMiami1Music- Silent Hill OST (True MoooZIC)Workshop ID: 3681477980 – Mod ID: SilentHillMusic- Cowboy Bebop OST (True MoooZIC)Workshop ID: 3681476976 – Mod ID: CowboyBebopMusic- Metal Gear Rising: Revengeance Vocal Tracks (True MoooZIC)Workshop ID: 3681339955 – Mod ID: MGRRevengeanceMusic- Classic Roblox Music (True MoooZIC)Workshop ID: 3681335952 – Mod ID: RobloxClassicMusic- DELTARUNE Ch3+4 Music (True MoooZIC)Workshop ID: 3681334251 – Mod ID: DeltaruneCh34Music- Minecraft Alpha+Beta OST (True MoooZIC)Workshop ID: 3680972796 – Mod ID: MinecraftClassicMusicAdditional InformationThis exploit only affected Build 42 branches. Build 41 was not vulnerable to this specific issue.The security updates released for Build 41 today address a separate vulnerability identified during an internal audit. At this time, we have found no evidence that this separate vulnerability has been exploited.As with previous security fixes, we have updated the outdatedunstable branch to match the unstable branch to avoid leaving a known vulnerability accessible. Going forward, outdatedunstable will continue to lag one content update behind unstable.Quick Update NoticeWe have seen a lot of people misunderstanding this situation. The affected mods above are not the True Moozic mod, nor were they created by the author of the True Moozic mod. The affected mods were simply add-ons fo
Related Posts
Patch Notes for patch 1.21.1-f8
- ThePatchMaster
- April 7, 2026
- 2 min read
Race Day 1.21.1-f8 Patch NotesHello Mayors! We have a small patch for Cities: Skylines – Race Day. This patch…
The new, free update, ‘Beyond the Hive’, is coming March 17!
- ThePatchMaster
- March 13, 2026
- 3 min read
The new ‘Expeditions’ game mode is part of the ‘Beyond the Hive’ update: A high risk experience that drags…
7.40b Gameplay Patch
- ThePatchMaster
- December 23, 2025
- 3 min read
Patch 7.40b is out now and you can check out the patch notes here. In addition, over the last…