# Virus from a spam email from a sketchy BlenderMarket user

**URL:** <https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591>\
**Category:** Latest News\
**Tags:** news\
**Created:** [April 6, 2025, 11:48am UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591 "2025-04-06T11:48:17Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Oby1](https://blenderartists.org/user_avatar/blenderartists.org/oby1/32/709995_2.png) [@Oby1](https://blenderartists.org/u/Oby1)\
**Post date:** [April 6, 2025, 11:48am UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/1 "2025-04-06T11:48:17Z")

</div>

Hi yall, today I found a lovely shady .blend file:

 ![image](https://blenderartists.org/uploads/default/original/4X/7/e/1/7e140a443d20098cf4481a8504598023001c4c74.png)

I just wanted to make sellers and other blender artists aware.  
Blender auto-executes .py files depending on your settings.

I avoided this by turning it off and appending the .py files instead of opening the .blend file itself \<3

 ![image](https://blenderartists.org/uploads/default/original/4X/d/9/b/d9b6c14b6584f3342d5786de9bc5a593beefc28f.png)

 ![image](https://blenderartists.org/uploads/default/original/4X/6/a/c/6ac5f575813795f851f743fb2819b61a20bff6cb.png)

Stay safe yall! and turn off auto script execute.  
I do get shady DMs and emails every now and then, and this is not at all Blender Market’s fault. This is just regular internet life.

Cheerio!

---

<div class="post-metadata">

**Author:** ![magpie](https://blenderartists.org/user_avatar/blenderartists.org/magpie/32/1088632_2.png) [@magpie](https://blenderartists.org/u/magpie)\
**Post date:** [April 6, 2025, 1:17pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/2 "2025-04-06T13:17:58Z")

</div>

There’s an option in the `Save & Load` tab under the `Auto Run Python Scripts` checkbox, to add certain folders to an exclusion list.

I put my Downloads folder into that list. So anything I open from that folder won’t have the scripts run automatically. I can open a new file, and take a look at it before I move it somewhere more permanent.

---

<div class="post-metadata">

**Author:** ![joseph](https://blenderartists.org/user_avatar/blenderartists.org/joseph/32/1433056_2.png) [@joseph](https://blenderartists.org/u/joseph)\
**Post date:** [April 6, 2025, 1:22pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/3 "2025-04-06T13:22:56Z")

</div>

You downloaded an addon from an unsolicited, clearly spam, email, and you’re… Surprised that’s it’s malware? Yeah, that’s what happens when you click on download links in spam emails. That’s on you, man.

ETA: I’ve edited your title because it implies that the fault here is BlenderMarket’s, the fault here is exclusively with you not following basic computer security protocols that have been the same since the 90s

---

<div class="post-metadata">

**Author:** ![thorn](https://blenderartists.org/user_avatar/blenderartists.org/thorn/32/1035944_2.png) [@thorn](https://blenderartists.org/u/thorn)\
**Post date:** [April 6, 2025, 1:25pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/4 "2025-04-06T13:25:04Z")

</div>

Thanks for the reminder. Still can’t believe I have to worry about my 3D software being the source of a virus installer… Yay, modern life.

---

<div class="post-metadata">

**Author:** ![Memm](https://blenderartists.org/user_avatar/blenderartists.org/memm/32/977398_2.png) [@Memm](https://blenderartists.org/u/Memm)\
**Post date:** [April 6, 2025, 1:38pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/5 "2025-04-06T13:38:14Z")

</div>

This is the creator’s inbox, where we receive messages from customers. It wouldn’t be difficult to get a developer to open a .blend file thinking they’re helping a customer out with their problem. Also, I once had my antivirus flag an infected image simply browsing BM. This thread is a good reminder to be careful, there are plenty of malicious people on BM posing as real customers or creators.

---

<div class="post-metadata">

**Author:** ![joseph](https://blenderartists.org/user_avatar/blenderartists.org/joseph/32/1433056_2.png) [@joseph](https://blenderartists.org/u/joseph)\
**Post date:** [April 6, 2025, 1:41pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/6 "2025-04-06T13:41:28Z")

</div>

Right, but security procedure when dealing with an unknown and potentially dangerous file is to download it in an isolated virtual machine for analysis, then move it to your real hard drive once it’s safe. I can’t imagine most people do that, but they should- I maintain that this isn’t a BlenderMarket problem, you’d have the same issue downloading random .blend files from here, Reddit, Twitter, anywhere.

@magpie 's tip about auto-run exclusions is also a great mitigator here

---

<div class="post-metadata">

**Author:** ![Memm](https://blenderartists.org/user_avatar/blenderartists.org/memm/32/977398_2.png) [@Memm](https://blenderartists.org/u/Memm)\
**Post date:** [April 6, 2025, 1:45pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/7 "2025-04-06T13:45:05Z")

</div>

In a perfect world, sure. But imagine it’s 2am, I’m tired, someone says the addon isn’t working, they send me a .blend file. It’s very likely I’ll open it up to see what the issue is, without much thought. 🙂

Thankfully I just double checked and auto-run python is off by default. But this makes me wonder what other graphics files can be infected. 🤔

---

<div class="post-metadata">

**Author:** ![Oby1](https://blenderartists.org/user_avatar/blenderartists.org/oby1/32/709995_2.png) [@Oby1](https://blenderartists.org/u/Oby1)\
**Post date:** [April 6, 2025, 1:54pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/8 "2025-04-06T13:54:32Z")

</div>

I do apologise, and I knew exactly what was gonna be in the .blend. But I was curious what type of virus it was, so I extracted it without running. And I fully agree with the new title. Just wanted to tell folk about this message floating around.

---

<div class="post-metadata">

**Author:** ![Oby1](https://blenderartists.org/user_avatar/blenderartists.org/oby1/32/709995_2.png) [@Oby1](https://blenderartists.org/u/Oby1)\
**Post date:** [April 6, 2025, 2:00pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/9 "2025-04-06T14:00:42Z")

</div>

I did, I was just curious what the result would be. Had a fun time checking things out - safely

---

<div class="post-metadata">

**Author:** ![MartinZ](https://blenderartists.org/user_avatar/blenderartists.org/martinz/32/1437938_2.png) [@MartinZ](https://blenderartists.org/u/MartinZ)\
**Post date:** [April 6, 2025, 2:13pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/10 "2025-04-06T14:13:09Z")

</div>

It’s really not a smart idea to open any blend files from the internet if you enable auto execution. It would certainly not be anyone’s fault if you do. You do have to go to the preferences and enable it all on your own.

---

<div class="post-metadata">

**Author:** ![thetony20](https://blenderartists.org/user_avatar/blenderartists.org/thetony20/32/1121876_2.png) [@thetony20](https://blenderartists.org/u/thetony20)\
**Post date:** [April 6, 2025, 4:28pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/11 "2025-04-06T16:28:02Z")

</div>

> [@thorn](#):
>
> Still can’t believe I have to worry about my 3D software being the source of a virus installer…

Worse then that, what about your ‘smart fridge’ ([https://osintteam.blog/a-smart-fridge-a-hack-and-a-small-business-in-chaos-the-strangest-cyberattack-of-2025-221d4668f9bc?gi=fbbe29c84d05](https://osintteam.blog/a-smart-fridge-a-hack-and-a-small-business-in-chaos-the-strangest-cyberattack-of-2025-221d4668f9bc?gi=fbbe29c84d05))

> [@Memm](#):
>
> But this makes me wonder what other graphics files can be infected.

A JPG file, which is actually a hidden executable (this fact can be hidden much more sneaky then you may first think), but still actually shows a JPG image, but by the time you see that, it’s already run the code in the background and you are infected, without even knowing it.

> [@joseph](#):
>
> download it in an isolated virtual machine for analysis, then move it to your real hard drive once it’s safe. I can’t imagine most people do that

Half the people don’t even have off-line backups or file versioning with warnings/notice, so I think it’s safe to say expecting virtual machines, etc just isn’t going to happen 99.9% of the time.

Strangely enough, anyone with a modern Windows install (and recent CPU with VM enabled) has Windows Sandbox built in. A totally isolated VM and you can spin up in a few seconds and once closed, it gets completed destroyed.

Only side note is that it’s Windows Pro only, but personally I’ve only ever ran the ‘Pro’ version.

---

<div class="post-metadata">

**Author:** ![thorn](https://blenderartists.org/user_avatar/blenderartists.org/thorn/32/1035944_2.png) [@thorn](https://blenderartists.org/u/thorn)\
**Post date:** [April 6, 2025, 4:39pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/12 "2025-04-06T16:39:33Z")

</div>

> [@thetony20](#):
>
> Worse then that, what about your ‘smart fridge’

Yeah, I don’t buy kitchen appliances with wifi and Bluetooth and touch screens.

Don’t know why anyone does…

---

<div class="post-metadata">

**Author:** ![Memm](https://blenderartists.org/user_avatar/blenderartists.org/memm/32/977398_2.png) [@Memm](https://blenderartists.org/u/Memm)\
**Post date:** [April 6, 2025, 5:22pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/13 "2025-04-06T17:22:46Z")

</div>

BM just sent out an email regarding this saying they’re taking measures. Not sure what they could do, but at least we know they’re aware and are making everyone else aware too. 🙂

---

<div class="post-metadata">

**Author:** ![unskilled](https://blenderartists.org/user_avatar/blenderartists.org/unskilled/32/1068333_2.png) [@unskilled](https://blenderartists.org/u/unskilled)\
**Post date:** [April 6, 2025, 5:38pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/14 "2025-04-06T17:38:51Z")

</div>

I got that email from BM as well. Not long after I got the same or similar spam message OP posted about. BM marked it as spam and said to not click on links from that user. This was all in my email before even logging into BM so they are def on top of it.

---

<div class="post-metadata">

**Author:** ![unskilled](https://blenderartists.org/user_avatar/blenderartists.org/unskilled/32/1068333_2.png) [@unskilled](https://blenderartists.org/u/unskilled)\
**Post date:** [April 29, 2025, 1:10am UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/15 "2025-04-29T01:10:01Z")

</div>

FYI it looks like there’s another spam message going out to creators. Very similar to what OP posted. General praise. Vague request for doing new work. Sketchy .zip attached. I don’t know sender and I wasn’t expecting this message.

I sent an email to support but I’m sure I’m not the only one receiving this. Stay alert.

---

<div class="post-metadata">

**Author:** ![Oby1](https://blenderartists.org/user_avatar/blenderartists.org/oby1/32/709995_2.png) [@Oby1](https://blenderartists.org/u/Oby1)\
**Post date:** [April 29, 2025, 2:23pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/16 "2025-04-29T14:23:48Z")

</div>

Curious if it’s the same scammer/bot. Was the DM from “Brian”? Got one last night.

---

<div class="post-metadata">

**Author:** ![unskilled](https://blenderartists.org/user_avatar/blenderartists.org/unskilled/32/1068333_2.png) [@unskilled](https://blenderartists.org/u/unskilled)\
**Post date:** [April 29, 2025, 2:30pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/17 "2025-04-29T14:30:51Z")

</div>

Mine was from “Constance”. Superhive is on it though, they flagged the message and removed it. Also they just sent out an email about a different phishing attempt asking to verify bank payments. Ugh.

---

<div class="post-metadata">

**Author:** ![Oby1](https://blenderartists.org/user_avatar/blenderartists.org/oby1/32/709995_2.png) [@Oby1](https://blenderartists.org/u/Oby1)\
**Post date:** [April 29, 2025, 2:32pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/18 "2025-04-29T14:32:58Z")

</div>

daymn. They got it hard. I usually get facebook scams and stuff. never thought the scammers would go for 3D sites

---

<div class="post-metadata">

**Author:** ![unskilled](https://blenderartists.org/user_avatar/blenderartists.org/unskilled/32/1068333_2.png) [@unskilled](https://blenderartists.org/u/unskilled)\
**Post date:** [April 29, 2025, 2:34pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/19 "2025-04-29T14:34:23Z")

</div>

Wherever they think there’s money. Simple as that.

---

<div class="post-metadata">

**Author:** ![joseph](https://blenderartists.org/user_avatar/blenderartists.org/joseph/32/1433056_2.png) [@joseph](https://blenderartists.org/u/joseph)\
**Post date:** [April 29, 2025, 2:40pm UTC](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591/20 "2025-04-29T14:40:42Z")

</div>

I just sent them an email:

To whom it may concern,

In the last two weeks, I and many other Superhive customers have received unsolicited emails seemingly sent to all Superhive customers from sellers I have never interacted with or consented to receive email from. These emails contain viruses in the form of attached .zip files. These emails are from Superhive and on Superhive stationery. You are responsible for the unauthorized use of my personal data and email. You are responsible for divulging my email without consent. You are responsible for sending me emails without consent.

In light of this extremely disturbing behavior, I must request a clear answer to each of the following questions from your Compliance Officer or their representative in the next 24 hours. Your voluntary response would be preferred, I would prefer not to involve legal representation, but I will absolutely do so if this goes unanswered.

1. Why are random sellers able to contact me on Superhive without my consent?
2. What precautions are you taking to secure your database containing personal information including emails?
3. What parties have you shared the mentioned database with?
4. Why are there no precautions in place to check sent messages for viruses or malware?
5. Why are you lending your logo, mail servers, and brand to cyber criminals without any form of screening?
6. What steps are you taking to immediately secure your database, protect my personal information, and remedy this situation?

Thank you for your prompt and thorough response.

Joseph Hansen

[Next page](https://blenderartists.org/t/virus-from-a-spam-email-from-a-sketchy-blendermarket-user/1587591.md?page=2)
