Beware of people posting addons

I’ve seen a number of suspicious posts, usually vibe-coded things where the first post is someone offering some cool new tool for “free”. But the repo they direct you to is brand new, and they have no online presence beyond a brand new GitHub. typically their post was clearly made by an LLM.

I strongly recommend you not download any free executables.

9 Likes

I’m always suspicious, of suddenly getting a completely unsolicited email about a service or product I’ve never heard of or have any idea of their motives.

‘Website Launches’ is a good example. Got an email from them after getting the site up and running, they apparently already have my site listed and I need to log in to confirm it’s mine. All I could find online about them was hundreds of people asking if they are a scam, and a result saying they ‘May’ be a legitimate service but take care.

I was thinking that is it possible to launch malwares using Godot addons?

I believe it’s very possible.
Never trust any random addon!

1 Like

Possible? I think it might be insanely easy.

Someone just has to actually put in some effort, speak proper English for once, and play the long game instead of pump-n-dumping LLM slop.

Maybe @HyperJragon could have a word about this.

(I am absolutely going to talk about this on the Monkanics discord. This is way too interesting)

2 Likes

OS.execute()

In short, yes. It’s insanely easy.