That was quick
Looks like it’s becoming BlenderVirus._com … fun.
The comments in the other thread about their new name sounding like something a malware group would come up with was supposed to be a joke.
Now you have actual shady activity attempting to deliver malware, almost as if the market was some shady vendor that crawled out of the dark web. They could easily go the way of Blendswap before them if they do not sort out their IT and security code.
Didn’t see this thread before posting my own rabbit hole: Blend files can execute malware
TLDR: It’s a pyramid of scripts that download and run themselves, embedding and hiding themselves in your system.
Each layer is obfuscated, encrypted, and/or in another language (programming or literary), making it hard to tell what it does, other than “something sketchy”.
The last layer I could reach times out so I couldn’t see what this malware actually does, which is not to say it doesn’t do anything, but that the authors can remotely enable the service at any time, which will trigger your machine to run whatever code they want. Instantly. You won’t even know it’s happening.
Well, it’s a good thing that turning this off shuts down all network access for Blender.
…oh wait… that’s right, it doesn’t do that…
As this is an ongoing issue that has not been resolved yet by Superhive, I’m pinning this globally to caution BA users to be judicious about using Superhive for now
I did get a reply from Superhive, which I’m not going to editoralize but present without comment:
-
Why are random sellers able to contact me on Superhive without my consent?
As a Creator on Superhive, your customers and potential customers can contact you via the Superhive inbox with any questions they may have regarding your products or your work. They do not have your personal contact information. -
What precautions are you taking to secure your database containing personal information including emails?
We are following all GDPR and consent requirements. As I stated, no one has your personal information and are only contacting you via the Superhive inbox. If you have any evidence otherwise or something you would like us to investigate, please do send it our way. -
What parties have you shared the mentioned database with?
We have not shared our database with any outside parties. -
Why are there no precautions in place to check sent messages for viruses or malware?
We do have precautions in place that scan inbox messages for suspicious content, marks that content as spam and automatically blacklists the sender. We are also in final testing for implementing email verification as well. -
Why are you lending your logo, mail servers, and brand to cyber criminals without any form of screening?
I’m not sure what you mean by this, but assume you are referring to receiving messages via the Superhive inbox. If I am missing something here, please do clarify so we can investigate further. -
What steps are you taking to immediately secure your database, protect my personal information, and remedy this situation?
I believe this is answered in the collection of responses above. We are also looking into 2FA.
Emphasis on “potential customers”, which I suppose is the entire world.
Hell, even this forum requires more new-user time on deck, before allowing attachments to be posted. You can’t just make a new robo account here and immediately spam us with zip files.
Which leads me to the next question, is there any reason for any non-customer to be able to send an attachment to a creator on Superhive?
A text message sure, people could have questions before wanting to make a purchase and an actual customer may need to send a problem .blend file and the like.
That is a most excellent point.
I didn’t want to directly editoralize the reply, but yes, this is insane. The fact that it is- according to the reply- intended behavior means I will delete my Superhive account
I’ll take a wild guess, and say that my personal practices and paranoia level about computer security are far lower than a lot of people on this forum.
I find automatic window updates to be far more annoying than whatever benefit they might offer, and usually disable it for months at a time. I do not subscribe to the theory that I must keep my computer updated 24/7, to avoid terrible things happening in my life.
I’m old enough to have lived in a time that you needed to use some common freaking sense on your own, to avoid getting screwed over by hackers. Virus protection program back then was an aid, not a complete cure.
That’s still how I approach online life. I rely more common sense than automated processes and patches. I have been infected by a virus exactly once in my life, and that was back in 1998. It was also 2:00 in the morning, and I double clicked the file without thinking, and immediately knew I had screwed myself… Fortunately, everything was fine about 12 minutes later.
Having said all of that, the situation with blender market is incredibly troubling to me. And I’ll certainly be using gumroad instead of blender market, in the future, when that’s an option.
I got one of these the other day, sounded phishy when he was asking an addon developer to create 500 renders. I checked with the BlenderMarket who confirmed it was a phishing scam.
The rule of thumb is never download anything from anyone unless they’re an existing customer, and even then, make sure to disable the trusted source option in the file open window’s n panel (just in case someone has already infected the user’s file).
I can’t share the exact message because it’s been automatically remove now, but it was from someone called Richard wanting 500 interior models rendering.
Of course, but the point stands- why can someone that isn’t a customer send me files at all?
I do occasionally get people asking whether the addon will help with a specific scene before they purchase. I think even if Blender Market disabled attachments from non-customers, they could still include a dropbox link etc. Perhaps they just need to update their spam filter ![]()
Is it also possible for sellers to pull their assets and addons from the store as well (because a rapid decline in the number of products to buy would surely get their attention)?
The ongoing situation also reminds me that these people also were the ones running Blenderartists at some point, despite my disagreements with the way Blendernation has run things at times, I do shudder at what could’ve happened otherwise considering how Superhive runs their own stuff.
In Blender Market’s defence, they are being vigilant as far as notifying users when one is recognised, and it’s very difficult to accurately identify spam. They also automatically remove them after identification.
I’ve only ever received one spam/phishing email via their ‘ask a creator’ system, so perhaps it’s not that prevalent anyway (at least in my case).
The short answer to this is no. You have to email Superhive and ask permission to have a product removed. Which means they could reject your request.
Also to the point of the word customer. Unless they’ve changed the system since becoming Superhive all customers belong to them. As a creator I have zero access to any information other than someone bought my thing. Yet they throw it at me to provide support. I don’t mind providing support but how am I supposed to know a given person who contacted me actually bought my thing?
I’m up to three over the last 11 days or so


