The largest collection of malware source code, samples, and papers on the internet. Password: infected

International
Yeah, so I decided to check out the Steam goop people were DMing me about. Basically there is something called People's Playground (I have no idea what that is) and they started discussing a malicious Steam mod thingie surrounding it. However, the malware is not specific to them but is a much more broad issue. Interestingly, this is a Steam mod worm. I have never seen anything like this before. I found it very silly. What I did not find silly, and I actually found it very ... confusing ... was the payload in all of this. Once this Steam worm thingie is detonated on your machine it - Deletes browser cookies (???) - Deletes photos from "MyPictures" on Windows - Deletes videos from "MyVideos" on Windows - Tries to "destroy" Steam friends, apps, etc Throughout the entire payload I was looking for something else, like data exfiltration, or a broader malware campaign, ... but all this does is try to fuck up Steam, delete gunk off your computer, and then self-spreads by making the Steam user publish a mod. Some gamer nerd guy person did a write-up on it. I'll link it. I verified everything they wrote and they're correct on it. I just don't get it though. This guy could have had a semi-successful information stealer campaign, or pay-per-install campaign, ... or crypto theft, ... or anything. but all it does is fuck up your Steam locally. Like, all you need to do is reinstall Steam. I don't understand.
54
39
902
31,498
Write-up which is factually accurate and cool studiominus.nl/ppg-september…
1
4
99
6,063
Good news for malware nerds who care about actual malware stuff I do for vx-underground. Updates to vx-underground will be temporarily suspended as we experiment with ultra mega fuck off VXUG It will be a beta. I also need to contact @BobDaHacker but I keep forgetting
5
5
306
17,480
WHY DON'T I GET FREE MALWARE
Had an "interview" for a blockchain project last week. Camera was on, we're chatting, and the guy tells me to clone a GitHub repo and run it locally before we go further into the technical round. I said sure, but first can you do me a favor hold up 3 fingers in front of your face for me real quick. He froze. Didn't move. Just sat there for a few seconds before the call cut off and he blocked me. That's when I knew. A real interviewer doesn't glitch out over a random ask like that. A deepfake/AI overlay does. These "run this repo" scams are getting scary common in crypto and dev hiring right now. The setup is always the same: - flattering DM - real-sounding project - rushed timeline - a "quick step" before the call that's really just remote access or a credential stealer in disguise. If someone wants you to run code or install something before you've even had a real conversation, that's the whole scam. Trust the instinct. Stay safe out there.
13
30
991
39,031
Big news for malware enthusiasts: I've uploaded an additional 170,000+ malwares to the internet Bigger news for silly pictures of cats enthusiasts: I've attached one to this post
32
34
1,073
17,794
My bad, I forgot to attach the upload log thingie vx-underground.org/Updates
4
1
36
3,835
THE ANIME LADIES PREDICTED SHINYHUNTERS DESTROYING THE FEDS
Yo, we all gotta talk bout ShinyHunters vs PeopleSoft So let met get this right.. 113 of you said lets pack HR, payroll, finance, procurement, supply chain, student records, employee identities, and every business process with a pulse all into one giant loot piñata with an ugly @Oracle logo stamped on it? Love me a place where their leadership finally discovers "mission critical" means too important to patch, too entangled to isolate, too expensive to replace, and too embarrassing to explain. Congratulations kings. You all running a Threat Actor Costco and gave ShinyHunters an executive membership.
13
81
1,575
49,081
I got you dawg
Replying to @vxunderground
I enjoy the phrase “little people inside my computer” for some reason
15
32
996
28,177
Hello, Little People Living Inside My Computer, I have made a YouTube account to discuss malware reverse engineering and development. It will primarily target noobs. It will be lighthearted, poorly produced, and spontaneous. piped.video/@MalwareForFun
128
376
5,075
139,678
> "Two sources familiar with the matter ..." Dawg, they defaced the fucking FBIs website and published a letter online THREATENING THEM. They're EXTORTING the United States government. Only TWO sources??? 99% of cybersecurity nerds have seen the letter. But .. TWO SOURCES???
The FBI is investigating an apparent breach of its networks after a prolific cybercriminal group claimed on Tuesday to have stolen thousands of FBI agents’ personal data, two sources familiar with the matter tell @snlyngaas & @evanperez. cnn.com/2026/09/22/politics/…
28
81
1,561
74,291
I guess in all fairness this is probably reserved for non-schizo-nerds, but writing "two sources familiar with the matter" seems silly in this context.
8
2
199
7,421
> Top 100 tech influencers on Xitter > Look inside > CLAVICULAR in top 10 for TECHNOLOGY
Announcing the 2026 ETN100, the 100 most influential tech posters on X etnshow.co/top-100
37
41
1,493
40,157
Men's dress guy? Autism capitol? What the fuck? WHO ARE YOU PEOPLE? DO YOU EVEN WORK IN TECH
8
235
7,562
fbi job portal defaced and compromised? oh yeah, it's a silly tuesday
49
315
4,184
136,246
crime is illegal and for nerds. this is bad and it is criminal. don't compromise the fbi and extort them. that is bad
13
10
405
14,449
> wake up > take a shit > get out of bed > get on computer > check xitter > pornography all over timeline > ??? > wtf i dont horny on xitter > realize reposts > colleague horny posting on main
51
107
4,649
100,297
Seeing a lot of people online discussing the rapidly rising cost of gasoline due to some made up place called Bab El Mandeb and Hormuz. I'll give you a pro tip to save a few bucks at the pump: credit card fraud You're welcome
41
35
1,201
43,734
For the record this is a joke. Do not commit identity theft. That is very bad. Crime is bad and illegal
11
2
167
7,819
Chat, you're never going to believe it. Over the weekend I visited a family members child's birthday party. Fast forward approx. 48 hours and I am sick. Who could have imagined a dozen children would have been a vector for disease?
39
15
771
18,455
I'm "done" with the first video. I ended up substantially trimming it down and, per some feedback I received, focusing more on the secondary in-memory payload. It has taken me little over a week to make a video on a malware payload which would normally would only take me like... 30 minutes (or less) I can't spend over a week discussing a fairly common Malware-as-a-Service payload. I also don't have time to discuss Lumma internals. I initially planned on it, but it's too much for me at the moment. We have more malware to bonk with a stick. This is a "demo" run of me bonking malware with a stick videos. I'm weighing on whether or not I want to continue producing videos. It is fun, however it considerably slows me down on other malware thingies I want to look at it. I dunno. Here is the final cut:
62
105
1,392
41,287