Virus from a spam email from a sketchy BlenderMarket user

Hi yall, today I found a lovely shady .blend file:

I just wanted to make sellers and other blender artists aware.
Blender auto-executes .py files depending on your settings.

I avoided this by turning it off and appending the .py files instead of opening the .blend file itself <3

Stay safe yall! and turn off auto script execute.
I do get shady DMs and emails every now and then, and this is not at all Blender Market’s fault. This is just regular internet life.

Cheerio!

16 Likes

There’s an option in the Save & Load tab under the Auto Run Python Scripts checkbox, to add certain folders to an exclusion list.

I put my Downloads folder into that list. So anything I open from that folder won’t have the scripts run automatically. I can open a new file, and take a look at it before I move it somewhere more permanent.

8 Likes

You downloaded an addon from an unsolicited, clearly spam, email, and you’re… Surprised that’s it’s malware? Yeah, that’s what happens when you click on download links in spam emails. That’s on you, man.

ETA: I’ve edited your title because it implies that the fault here is BlenderMarket’s, the fault here is exclusively with you not following basic computer security protocols that have been the same since the 90s

3 Likes

Thanks for the reminder. Still can’t believe I have to worry about my 3D software being the source of a virus installer… Yay, modern life.

3 Likes

This is the creator’s inbox, where we receive messages from customers. It wouldn’t be difficult to get a developer to open a .blend file thinking they’re helping a customer out with their problem. Also, I once had my antivirus flag an infected image simply browsing BM. This thread is a good reminder to be careful, there are plenty of malicious people on BM posing as real customers or creators.

8 Likes

Right, but security procedure when dealing with an unknown and potentially dangerous file is to download it in an isolated virtual machine for analysis, then move it to your real hard drive once it’s safe. I can’t imagine most people do that, but they should- I maintain that this isn’t a BlenderMarket problem, you’d have the same issue downloading random .blend files from here, Reddit, Twitter, anywhere.

@magpie 's tip about auto-run exclusions is also a great mitigator here

1 Like

In a perfect world, sure. But imagine it’s 2am, I’m tired, someone says the addon isn’t working, they send me a .blend file. It’s very likely I’ll open it up to see what the issue is, without much thought. :slight_smile:

Thankfully I just double checked and auto-run python is off by default. But this makes me wonder what other graphics files can be infected. :thinking:

3 Likes

I do apologise, and I knew exactly what was gonna be in the .blend. But I was curious what type of virus it was, so I extracted it without running. And I fully agree with the new title. Just wanted to tell folk about this message floating around.

4 Likes

I did, I was just curious what the result would be. Had a fun time checking things out - safely

3 Likes

It’s really not a smart idea to open any blend files from the internet if you enable auto execution. It would certainly not be anyone’s fault if you do. You do have to go to the preferences and enable it all on your own.

3 Likes

Worse then that, what about your ‘smart fridge’ (https://osintteam.blog/a-smart-fridge-a-hack-and-a-small-business-in-chaos-the-strangest-cyberattack-of-2025-221d4668f9bc?gi=fbbe29c84d05)

A JPG file, which is actually a hidden executable (this fact can be hidden much more sneaky then you may first think), but still actually shows a JPG image, but by the time you see that, it’s already run the code in the background and you are infected, without even knowing it.

Half the people don’t even have off-line backups or file versioning with warnings/notice, so I think it’s safe to say expecting virtual machines, etc just isn’t going to happen 99.9% of the time.

Strangely enough, anyone with a modern Windows install (and recent CPU with VM enabled) has Windows Sandbox built in. A totally isolated VM and you can spin up in a few seconds and once closed, it gets completed destroyed.

Only side note is that it’s Windows Pro only, but personally I’ve only ever ran the ‘Pro’ version.

3 Likes

Yeah, I don’t buy kitchen appliances with wifi and Bluetooth and touch screens.

Don’t know why anyone does…

3 Likes

BM just sent out an email regarding this saying they’re taking measures. Not sure what they could do, but at least we know they’re aware and are making everyone else aware too. :slight_smile:

5 Likes

I got that email from BM as well. Not long after I got the same or similar spam message OP posted about. BM marked it as spam and said to not click on links from that user. This was all in my email before even logging into BM so they are def on top of it.

5 Likes

FYI it looks like there’s another spam message going out to creators. Very similar to what OP posted. General praise. Vague request for doing new work. Sketchy .zip attached. I don’t know sender and I wasn’t expecting this message.

I sent an email to support but I’m sure I’m not the only one receiving this. Stay alert.

3 Likes

Curious if it’s the same scammer/bot. Was the DM from “Brian”? Got one last night.

Mine was from “Constance”. Superhive is on it though, they flagged the message and removed it. Also they just sent out an email about a different phishing attempt asking to verify bank payments. Ugh.

daymn. They got it hard. I usually get facebook scams and stuff. never thought the scammers would go for 3D sites

Wherever they think there’s money. Simple as that.

1 Like

I just sent them an email:

To whom it may concern,

In the last two weeks, I and many other Superhive customers have received unsolicited emails seemingly sent to all Superhive customers from sellers I have never interacted with or consented to receive email from. These emails contain viruses in the form of attached .zip files. These emails are from Superhive and on Superhive stationery. You are responsible for the unauthorized use of my personal data and email. You are responsible for divulging my email without consent. You are responsible for sending me emails without consent.

In light of this extremely disturbing behavior, I must request a clear answer to each of the following questions from your Compliance Officer or their representative in the next 24 hours. Your voluntary response would be preferred, I would prefer not to involve legal representation, but I will absolutely do so if this goes unanswered.

  1. Why are random sellers able to contact me on Superhive without my consent?
  2. What precautions are you taking to secure your database containing personal information including emails?
  3. What parties have you shared the mentioned database with?
  4. Why are there no precautions in place to check sent messages for viruses or malware?
  5. Why are you lending your logo, mail servers, and brand to cyber criminals without any form of screening?
  6. What steps are you taking to immediately secure your database, protect my personal information, and remedy this situation?

Thank you for your prompt and thorough response.

Joseph Hansen

5 Likes