Session Stealers Don't Hack You. They Become You.
Oct 1, 2026 · @Budget Engineer
I got hit by an infostealer/session stealer. And it started with the most boring sentence in tech: "hmm, my PC's acting a bit funny."
I still don't know how it got in. I've got guesses, but guesses aren't proof, so I'm not going to pretend I know. What I do know is exactly what it did once it was in.
How I found out
So I opened Task Manager, and a couple of things in there looked off. BlueSuite.exe and MSBuild.exe. Neither is something I'm used to seeing in there.
So I grabbed Malwarebytes and ran it. It flagged MSBuild.exe calling out to a domain called gamezklop.cc. That's the moment "acting a bit funny" turned into "oh no."
Pulling it apart
Once Malwarebytes flagged it, I yanked the internet. Then I went digging.
Took me about three hours to track it all down. Here's what was sitting on my machine:
A file called goat_aisle_ plus random characters. It kept re-dropping itself. I found copies dated the day before and the day I found it so deleting it once was never going to cut it.
MSBuild.exe doing its dirty work. MSBuild is a real Microsoft developer tool, signed and everything. Which is exactly why it's a good place to hide. Nobody looks twice at MSBuild.
A fake "BlueSuite.exe" dressed up as Bluetooth software, sat in a folder called InProcSvr32. That's a knockoff of InProcServer32, a real Windows thing. Cute.
A registry Run key that relaunched the lot every time I logged in. That was the actual thing keeping it alive.
A scheduled task called "BackgroundTask". Very creative.
That gamezklop.cc callout was the smoking gun. It went out on port 443, behind Cloudflare, so on the surface it looks like normal web traffic. But MSBuild has no business talking to some random domain, never mind that it was phoning home.
Malwarebytes flagged it as a Trojan. I didn't grab a file hash before I wiped, so I can't tell you which malware family it was. Panic mode ya know. Lesson learned.
What it actually took
Not just passwords. Sessions.
You know how you don't have to log in to Discord every time you open it? That's a session cookie sitting on your machine. Steal that, and you don't need the password. You don't need the 2FA code either. As far as Discord or Reddit is concerned, you are that person, already logged in.
Reddit first, because it was weird. It posted one comment on something, and it read like a normal person wrote it. It also subscribed me to a pile of NSFW subs I'd never touched. I nuked all of it the second I saw it, so no screenshots, sorry. My best guess is it was making the account look normal and active so it's worth more later. That's a guess though.
I also replaced my debit cards. Maybe overkill. Didn't care.
Discord
Discord is where it got loud.
It sent the MrBeast crypto scam to every friend I have. Then every server I'm in. Every channel it could post in. If you've been on Discord this year, you've probably had this exact message from someone you know. This time that someone was me.
That's bad enough. People I actually know got a scam from my real account, and it looked like it came from me. Because it did. (most knew it was a scam luckily)
But that's not the part that got me.
It also set every friend to ignored. So when people messaged going "mate, you've been hacked" or "is this actually you?"... I never saw it. No notifications. Nothing. The people trying to warn me were muted before they'd even typed a word.
Think about that for a sec. It used my friends trusting me to spread the scam, then made sure those same friends couldn't reach me to tell me. The spam was the noise. Muting everyone was the plan.
Wait, this isn't just me
Once the dust settled, I did what everyone does. I dug into it, half hoping I'd just been unlucky.
Nope. Not even close.
Thousands of Discord accounts doing the exact same thing
The MrBeast message my account sent? It's a whole wave. Bitdefender wrote it up in July: infostealers grab Discord session tokens, which lets attackers skip your password and "in some cases, two-factor authentication." Then the account spams its friend list with a fake MrBeast giveaway. They put it at "tens of thousands of compromised accounts" so far in 2026, and that's just the ones being counted. (Bitdefender)
Where do the infections come from? Bitdefender's list: "mods, cracked software, cheating tools, malicious browser extensions." Basically, stuff people download on purpose.
Then I hit Reddit, and found people describing my exact week. One person got their account back to find "like nearly a hundred ppl are ignored and muted." (r/antivirus) Another just said what everyone's thinking: "bro my account use 2fa and still got hacked."
So the muting wasn't a fluke. It's part of the playbook.
A Minecraft mod that actually works
In September a fake Minecraft mod showed up pretending to be an add-on for Lithium, a popular, legit performance mod. Here's the clever bit: 12 of its 13 features actually work. You install it, your game runs fine, you've got no reason to be suspicious. The 13th one quietly pulls down a stealer called Myth Stealer from Dropbox. When it was first found, VirusTotal didn't flag it at all. Zero detections. (GBHackers)
What does it steal? Saved passwords, browser cookies, sessions. Sound familiar?
Quick note because a lot of headlines got this wrong: it wasn't on CurseForge or Modrinth. It got passed around through Discord and chat links, wearing Lithium's name. Nobody hacked a mod store. They just borrowed a name people already trust.
Steam Workshop, twice over
If you play anything with mods on Steam, this one's for you.
MECCHA CHAMELEON is a $5 indie game that sold 15 million copies in a month. In July, someone uploaded custom maps to its Steam Workshop that looked completely normal. Buried in the map files was a hidden bit of logic that ran the moment the map loaded, dropped a batch file into your Documents folder, and quietly started pulling more malware from the internet. (Windows Central)
Then it got worse. In the developer's own words: "a system engineer's PC was infected with malware. The hacker bypassed the engineer's Discord 2-Factor Authentication (2FA), took over server permissions, and banned all official staff members."
Read that again. The game's official Discord got hijacked, 2FA and all, and the people who actually run it got banned from it. Getting past 2FA like that sounds an awful lot like the same session-stealing trick that got me, just aimed at a much bigger target.
People Playground got hit twice this year, in February and again in September. The second time, a malicious mod could wipe your personal files, read your Discord, and publish more infected mods to the Workshop on its own so it kept spreading. The developer ended up switching off the Workshop and telling everyone to "delete all your mods in your mods folder and do not open the game" until it was safe. (Kotaku)
The Workshop is the official, built-into-Steam place to get mods. That's exactly why people trust it.
It even got GitHub
This one's the developer side of things, but stick with me, because it's the same move at a much bigger scale.
In May, attackers poisoned some popular code packages (TanStack, if you're a dev). One of those got pulled onto a developer's machine at a company called Nx during a totally normal install. That handed the attackers their login.
A week later they used it to publish a poisoned update of Nx Console, a popular VS Code extension. Published by a real Nx account. Microsoft's automated checks looked at it and let it through. It was only live for about 11 minutes, but VS Code auto-updates extensions, so 11 minutes was enough. (Nx postmortem)
One of the machines that grabbed it belonged to a GitHub employee. GitHub confirmed attackers walked off with internal repositories. The attackers claim around 3,800 of them, and GitHub said that's "directionally consistent" with what they found. (GitHub)
And my favourite line from the whole thing, from Nx's own write-up: "We did not detect this through any system we built." Someone just happened to read a notification email.
(There's also a whole worm called GlassWorm that's been doing this through VS Code extensions since late 2025. Same idea, it needs its own full write up.)
Four totally different places. A chat app, a Minecraft mod, Steam's own mod store, a developer tool. Nobody cracked any encryption. Nobody found some genius zero-day.
They all did the same thing.
It has a name: trust chains
When we picture getting hacked, we picture someone breaking in. Guessing passwords, finding some bug, hoodie, green text, the whole movie thing.
None of these attacks broke in. They got let in.
That's what people mean by a trust chain attack. You trust something because you trust whatever's behind it. You trust a message because you trust the friend. You trust a mod because you trust the name on it. You trust an update because you trust the publisher, and the store that checked it. Each link vouches for the next one.
Attackers have figured out they don't need to beat the lock. They just need to grab one link in that chain, and everything after it trusts them automatically.
| Attack | What people trusted | What the attacker actually took over |
|---|---|---|
| My Discord | A message from me | My logged-in session |
| Myth Stealer | The Lithium name | Nothing. They just copied the name |
| Nx Console | A real publisher, Microsoft's checks, auto-update | One developer's login |
Look at that last column. It's tiny every time. One session. One name. One login. That's all it took to reach thousands of people.
Why 2FA didn't save anyone
This is the bit that trips people up, me included.
2FA protects the front door. It checks if it's really you when you log in. But a session cookie means you're already in. The attacker isn't logging in as you. As far as Discord's concerned, they're just... you, carrying on where you left off. The front door never comes into it.
And it's not the victims being thick
On Reddit, one of the replies to a MrBeast victim was basically "Discord didn't get hacked, you let your credentials get stolen." I get the instinct. But think about what actually happens.
They didn't fall for some random scam account. They got a message from someone they know, on an account they've talked to for years. Trusting that isn't stupid. It's literally the point of having friends on there.
Could also have been a trusted site, a trusted developer, or in some cases an auto update. Yes some session stealers are the fault of the user but not all.
That's why this works so well. It doesn't target dumb people. It targets normal behaviour.
Why it keeps working
So why is this so easy? It's not one bug someone forgot to patch. It's how a lot of our software is built. Three things keep coming up.
1. Auto-update with no second look
You check out an extension or a mod when you first install it. Read the page, look at the downloads, maybe the reviews. Fine.
Then version 47 shows up in the background while you're asleep, and nobody looks at that one. Not you, and often not the store either.
Raphael Silva at Aikido Security put it bluntly after the GitHub breach. His section heading was literally "Auto-update is the actual problem." His closing line: "every popular extension is one stolen token away from turning into a worm." (Aikido)
To be fair, auto-update isn't evil. It's how most people get security fixes at all, because let's be honest, nobody updates anything manually. The problem is when a new version quietly inherits all the trust you gave the old one, even though it now does something completely different.
2. The badge checks the account, not the code
"Verified publisher" sounds like it means "safe." It doesn't. It means the account is real.
Nx Console was published from a real Nx account. Every badge was technically true. And Microsoft's checks still let it through. In Nx's own words, it "passes the automated verification from Microsoft (signing checks, manifest validation, basic malware scans)." (Nx)
Scanning can only catch what looks bad. A sleeper that's clean today and nasty next week sails through.
3. Everything gets full access
This is the big one for me.
When you install a VS Code extension, it can do pretty much anything you can do. A colour theme, a thing that literally just changes colours, can technically read your SSH keys. A Minecraft mod is just code running on your PC. It can read your browser stuff the same as any other program. Same goes for whatever got onto my machine.
There's no "this mod only needs to touch the game folder" setting. It's all or nothing, and it's always all.
People have been asking Microsoft to add proper permissions to VS Code extensions since 2018. The request is still open. (GitHub issue #52116)
What the platforms actually did
Some of them did something. Mostly speed bumps.
Microsoft added a 2-hour wait before VS Code auto-updates an extension. Sounds good. Except "trusted publishers" like Microsoft, GitHub and OpenAI skip the wait. You know, the accounts that'd be most worth hijacking. (The Hacker News)
The US government (CISA) told people to "wait at least three hours before pulling a new package." (CISA) When the official advice is "don't trust anything new for a few hours," that tells you something.
GitHub made Dependabot, its tool that suggests updates, wait 3 days before suggesting a new version.
npm (where JavaScript packages live) started scanning packages when they're published. Which helps, until something's clean on day one and turns bad in an update.
Valve removed infected Workshop content after the fact. I couldn't find any change to how the Workshop works. The People Playground developer had to switch mods off for the game entirely, and when MECCHA CHAMELEON's story first broke, Valve hadn't even confirmed the bad map was gone.
Discord? I couldn't find a single public statement about the MrBeast wave. Nothing. The cleanup is mostly being done by third-party bots like RaidProtect.
Notice what none of these do. They slow things down, or scan a bit harder. Nobody changed the actual problem: that once something's in, it gets everything.
Someone's actually trying
While I was digging into all this, I stumbled on something that made me go "oh, finally."
Cloudflare has built a website system called EmDash. Yes, EmDash. Funny name for something I'm about to say nice things about. It's pitched as the "spiritual successor to WordPress," and it came out as an open-source beta in April. (heise)
The interesting bit isn't the website stuff. It's how it handles plugins.
WordPress plugins get the run of the place. Install one and it can touch your database, your files, everything. Cloudflare says 96% of WordPress security problems come from plugins. That's their number, not an independent one, but anyone who's run WordPress won't be shocked.
EmDash flips it. Every plugin runs in its own little sandbox, and it has to say up front exactly what it needs. Things like "read content" or "send email." It gets those, and nothing else. Doesn't say it needs the internet? No internet. (DevClass)
That's the exact thing missing from everything above. Not better scanning. Just don't hand out the keys to the whole house. Cloudflare's confident enough that it moved its own blog onto it in August. (Cloudflare)
Before anyone gets too excited
I'm not telling you to go switch your site. There are real catches:
The sandbox only works on Cloudflare. If you self-host it, sandboxed plugins aren't supported. So for us homelab people, the cool part doesn't come with it. WordPress founder Matt Mullenweg reckons it was "created to sell more Cloudflare services." He's hardly neutral, but he's got a point. (PPC Land)
Nobody's tried to break it yet. It's still pre-1.0 and there's barely a plugin ecosystem to attack. Talk is cheap until someone hostile has a go.
It limits the damage, it doesn't stop the hijack. If someone takes over a plugin's account, they can still push a bad update. It just can't reach as much. Chrome extensions have had permission lists for years and still get bought and turned bad.
It wouldn't have saved me. My problem was a Windows PC and stolen browser cookies. A sandboxed website builder does nothing for that.
So it's not a fix for all of this. But it's proof the fix people keep asking for can actually be built. Somebody just has to want to.
So what do you actually do?
Platforms are slow. Fine. Here's what you can do yourself, mostly stuff I learned the hard way or picked up from other victims on Reddit. Not much of it shows up in the usual "stay safe online" posts.
If you think you've been hit
Pull the internet first. Stop it phoning home and stop it grabbing anything else.
Recover from a different, clean device. Your phone, a mate's laptop, whatever. Not the infected machine.
Order matters. Log in, kick out every session ("log out of all devices"), then change your password and reset 2FA. If you change the password while their session's still alive, they might just carry on.
Check your email forwarding rules. This one barely gets mentioned. If they set up a rule forwarding your mail somewhere, it survives a password change and quietly keeps copying everything out. Check it before anything else on your email.
Wipe it, don't just scan it. Antivirus saying "all clean" doesn't make stolen sessions safe again, and you can't be sure what got left behind. I reset Windows. Panic mode, but the right call.
If you saved cards in your browser, assume they're gone. Mine weren't saved locally, but I had cards on file with a few sites, and after a week like this.... I replaced them anyway.
If it got your Discord
Go through your ignored and blocked lists and undo everything you didn't do yourself. Chances are some of your friends are in there.
Delete the scam messages it sent, so nobody else clicks them later.
Message people and explain. It's awkward. Do it anyway. A few people on Reddit said the apology round was the most important part after securing their account.
Stopping it next time
A "try my game" or "test my mod" file from a friend is still a file from a stranger until you've checked with them some other way. Text them. Call them. Their account might not be them.
Cracks, cheats and "free" versions of paid stuff are the number one way these stealers get in, according to basically every write-up I read. Not judging. Just know that's the deal.
Get mods from the real source. Fake mods ride on real names. Check the author, the download count, and how long it's been up. A day-old upload of a famous mod is a red flag.
Use a password manager and proper 2FA, but know what they don't cover. They protect logging in, not a session that's already been stolen.
Of course none of this list stops a supply-chain hit like GitHub/Nx Console, or a sleeper extension that turns bad in an update.
What I changed: my daily driver is Linux Mint now, my email moved to Proton with 2FA, and I've moved 40+ accounts over so far. Is Linux magic? No. But it has fewer attacks aimed at it and it got me a clean start and made me actually go through every account I've got. Also not staying logged into sites or apps.
For the devs
Turn off extension auto-update in VS Code (
"extensions.autoUpdate": false) and update on purpose.Pin your versions and set a minimum release age in your package manager.
Then check the setting actually works. The Nx developer had a "wait 7 days" setting, and their version of pnpm silently ignored it. That one gap is how the whole GitHub chain started.
The bit I keep coming back to
The stolen logins, the spam, the weird Reddit comment, I can deal with all that. Passwords change. Cards get replaced.
What stuck with me is the ignore. Somewhere out there are friends who saw that MrBeast message, knew it wasn't me, and tried to tell me. And I never heard them.
So here's the one thing I'd actually ask you to do. Next time a mate's account sends you something that's obviously not them, don't just mute it and move on. Text them. Call them. Use literally anything that isn't the account that's been taken.
Because their Discord might not let your warning through.
It's been a rough few weeks, maybe some of this helps someone else out there.

