Proprietary 2024-10-28 · 3 days ·Cryptocurrency Theft, Remote Code Execution

Traffic mod loaded wallet-stealing DLL

A compromised Traffic mod author account pushed fastmath.dll through Paradox Mods. Cities: Skylines II loaded the DLL, which targeted Exodus cryptocurrency wallets.

Story

The affected package was Traffic, a code mod for Cities: Skylines II distributed through Paradox Mods. Late on October 28, 2024, an outside actor pushed an unauthorized update that added fastmath.dll to the mod directory.

Paradox later determined that this was a DLL hijacking attack. When players launched the game with the affected mod installed, the game executable loaded the malicious DLL. The first stage then looked for Exodus wallet data under the user's local AppData directory.

Paradox removed the malicious file, worked with the mod author to secure the account, and said version 0.2.4 was safe as of October 31, 2024 at 15:35 CET. The company also scanned Paradox Mods for the same malicious file and added update notifications so creators could see unexpected changes sooner.

The distribution path matters because the mod was real and popular inside the game's official mod ecosystem. Players did not need to visit a phishing site; subscribing to or updating the trusted Traffic mod was enough to place the DLL where Cities: Skylines II would load it.

Affected Artifacts

mods/80095

paradox mods · mods.paradoxplaza.com · Game Mod
Observed
2024-10-28 to 2024-10-31
Compromised Versions
Unknown
Fixed
0.2.4
Evidence
distribution: mods.paradoxplaza.com/mods/80095/Windows, mirror: paradoxinteractive.com/games/cities-skylines-ii/news/traffic-breach-statement, file: fastmath.dll, file: %localappdata%low\Colossal Order\Cities Skylines II\.cache\Mods\mods_subscribed\80095_13 , +1 more
  • Paradox identified folder 80095_13 as the affected local mod directory and stated that version 0.2.4 was safe after removal of the malicious file.
  • The exact malicious version identifier was not stated in the official advisory.

Incident Context

Motive
Cryptocurrency Theft
Cause
Compromised Account Credentials
Transitive
No

External References

Source record: proprietary/cities-skylines-traffic/meta.yaml