Cicadas Posted 4 hours ago Report Posted 4 hours ago I want to continue to support Vintage Story and have done so by buying several VS keys (approx $330 worth) and distributing them via raffles on my community discord, now I no longer feel comfortable with further supporting VS. I want to see VS succeed and be the best it can, but I don't see that vision right now. I am disappointed but not surprised. I do not think Tyron's statement and actions are sufficient. I do not think the Vintage Story Dev team comprehend the severity of Maltiez's actions, the Dev team's own inaction (or knowledge of what Maltiez did) or the bigger picture ramifications it presents. I think Anego Studio failed to address and effectively deal with the root of the problem, which was another pay-for-use (and its free-to-use variant) illegal mod being distributed to the community. I think Anego Studio withheld information of malicious code tied to one of their developers and failed to communicate, inform, educate and protect its community. My trust in Vintage Story and Anego Studio has been significantly damaged as they have decided to keep Maltiez on the development team, to include their code contributions regardless of it being under more scrutiny. This incident and VS's actions onward will be something I strongly consider as I host Vintage Story vanilla and Modded for my community and the mods that are available in ModDB. Mods that run on my own server equipment, equipment that could be running malicious code in ways I have no immediate way of detecting. A similar incident that reminds me very strongly of what VS is dealing with, is StarSector and how it was handle by their lead Dev, Alexander Mosolov. Do better Anego Studio, learn from this mistake and do not ever repeat it. 1. What the real problem is, undisclosed malicious code execution distributed by ModDB crafted by a Vintage Story Dev. 2. VS/Anego Studio either deliberately or negligently withheld information about malicious code developed by a dev and deployed by their mods and showed a lack of ethics or judgement. 3. VS/Anego Studio failed to inform the community properly and take effective action. 4. VS/Anego failed to take proper actions dealing with an illegal pay for use mod. 5. A crisis/PR team is insufficient and not a solution, you need to genuinely address the problem of both bad faith and illegal mod makers. You need enforcement, auditing, and curation of modDB and stronger avenues of tackling TOS breaking mods. Otherwise vigilante code through mods is basically rubber stamped as "ok". Relevant Topics: - Should Maltiez's mods be removed from ModDB Yes. I do agree moving their mods to a custodianship is sufficient however I imagine it will put a strain on the VS Dev team till they find community trusted and reliable modders to take on Maltiez's mods. Should Maltiez be banned from Vintage Story Yes, effectively immediately and their development activities, to include their development contract with Anego Studios void. Maltiez should have no further ties now or in the future with Anego Studios. What should be done about Maltiez' code and development contribution to the VS Dev Team and Vintage Story proper? I think they should be removed completely and understand this will negative affect the combat update and development time. Scrutiny of the code must be intense, documented and open to audit. Communication after this should be transparent and clear. 4 7
Stellarbone Posted 4 hours ago Report Posted 4 hours ago (edited) The cost of keeping Maltiez is the trust of the community. He's shown his hand, his only remorse was being caught. It's bad enough the dev team knew and Tyron didn't talk about any of the false flags or Maltiez's response in his official response, but keeping a lying ai techbro on the team is too much. Edited 4 hours ago by Stellarbone 6 2
HalfAxd Posted 4 hours ago Report Posted 4 hours ago 3 minutes ago, Stellarbone said: The cost of keeping Maltiez is the trust of the community. Sorry, but no... you are not the community and you don't speak for me. If you don't like something, then you have the right to leave. At this point the rabble rousing is beyond absurd. Please say your peace and go. 3
Nossin Posted 3 hours ago Report Posted 3 hours ago Where is the justice for players and modders who were falsely targeted? What is stopping Maltiez from retaliating again? 7
Diff Posted 3 hours ago Report Posted 3 hours ago Just now, Nossin said: Where is the justice for players and modders who were falsely targeted? Genuine question, what are you seeking here? What would you feel is appropriate compensation for your videogame crashing intentionally? Just now, Nossin said: What is stopping Maltiez from retaliating again? He is no longer on the ModDB. He is no longer capable of uploading any mods at all. He is not and has never been capable of merging code into main directly. 5
Nossin Posted 3 hours ago Report Posted 3 hours ago 4 minutes ago, Diff said: Genuine question, what are you seeking here? What would you feel is appropriate compensation for your videogame crashing intentionally? He is no longer on the ModDB. He is no longer capable of uploading any mods at all. He is not and has never been capable of merging code into main directly. At minimum I would like Maltiez removed from the developement team so that there is not even a shred of a possibility of this happening again. I do not understand what Maltiez is contributing that is so essential to keeping them on the team after doubling down on distributing malware. 7
Cicadas Posted 3 hours ago Author Report Posted 3 hours ago (edited) I want to also thank members of the VS modding community and community at large for spotting Maltiez's malicious code and bring it to light to everyone. I look forward to other modders who take commitments to transparency, community building and safety strongly and forking away from Maltiez's mods. I hope the discussions here and in other forums and channels will remain respectful and that something genuinely good for the community as whole comes about and not the lackluster response that I am observing. I also want to recognize a common statement in both the reddit and other threads is that Maltiez's actions have affected Vintage Story Dev's community trust and the reputation of other modders by Maltiez's mod false positive'ing other modder's mods, crashing and even bricking some user's games and saves. This is serious, this is severe. This was deliberate and a malicious mod, a malware no different than what I would have to had deal with in my prior profession. Keenly. 1. Maltiez's behavior and conduct in the discord in other forms of communication being utterly disrespectful 2. Maltiez's actions affecting VS/Anego Studios' reputation. 3. Maltez's mods false positives against other modder's mods * and negatively affecting their reputations too I hope those unfairly banned will get reversed. Edited 3 hours ago by Cicadas Clarified statement 3. 4 1
Diff Posted 3 hours ago Report Posted 3 hours ago (edited) 17 minutes ago, Nossin said: At minimum I would like Maltiez removed from the developement team so that there is not even a shred of a possibility of this happening again. I do not understand what Maltiez is contributing that is so essential to keeping them on the team after doubling down on distributing malware. He's an employee. An employee can be a tricky thing to shed depending on your locality. Not everywhere allows you to snap employees out of existence at the drop of a hat. And the damage he can do is quite limited. You can't really sneak code like that past review, and every line of code (from any employee) is reviewed for behavior, correctness, and style. Apparently by Tyron himself. There really is no chance of it happening again. Edited 3 hours ago by Diff 1
Eruannon Posted 3 hours ago Report Posted 3 hours ago Just now, Diff said: He's an employee. An employee can be a tricky thing to shed depending on your locality. Not everywhere allows you to snap employees out of existence at the drop of a hat. And the damage he can do is quite limited. You can't really sneak code like that past review, and every line of code (from any employee) is reviewed for behavior, correctness, and style. Apparently by Tyron himself. There really is no chance of it happening again. Fun fact - there's such a thing as 'disciplinary termination of employment', in case of egregious violations, such as... malware distribution. As per 'no chance' - please, I'd honestly appreciate if You at least made half-reasonable claims. npm, PyPi, Go and Packagist, few of bigger linux packages, far more widely used than VS, verified by multiple expert programmers, managed to be targets and vectors of supply chain attacks in 2026, but somehow, a one-person validation turns it into 'no-chance' for violations? 2 1
Diff Posted 3 hours ago Report Posted 3 hours ago (edited) 1 hour ago, Eruannon said: npm, PyPi, Go and Packagist, few of bigger linux packages, far more widely used than VS, verified by multiple expert programmers, managed to be targets and vectors of supply chain attacks in 2026, but somehow, a one-person validation turns it into 'no-chance' for violations? I could really reflect your request for half-reasonable claims here... These are not at all similar situations. NPM, PyPi, and Go are the exact same story as the ModDB. Entirely unreviewed by anyone except the users. Go is especially egregious to include because it doesn't even have a centralized repository of any kind, you can upload to any public URL on the entire internet as long as it responds the way the Go expects. Linux distros are a closer analogy to this, and there are instances of maintainers going evil. But in the instances I'm aware of, they were trusted maintainers who didn't get their contributions reviewed at all, so we're back to being unreviewed here. We're not talking about the ModDB, which Maltiez is no longer present on. We're talking about the main VS codebase. Every line of code that gets submitted to VS gets reviewed by Tyron. These are flatly not the same situations, so yes, a one-person validation turns it into "no-chance" by virtue of it being a binary difference between "completely unreviewed" and "reviewed by a minimum of one person but sometimes more." How are you going to smuggle "accidentally" setting ClientMain to null past anyone with functioning eyes, let alone eyes that are scanning for multiple criteria? Edited 1 hour ago by Diff
icesharkk Posted 2 hours ago Report Posted 2 hours ago I also do not support retaining maltiez on the VS team. I do not trust his judgement and his continued involvement is a supply chain risk. He's done significant damage to the brand, the user base, and to the trust the userbase holds in VS and that isnt going to go away while he remains. It is possible that its the Latvian employment legalities that are contributing to this but he needs to have no access to the code. It is also quite disappointing that Tyron conspicuously did not mention any of users or mods harmed by maltiez in the execution of his crusade against one cheat client/mod. This whole uprising you are seeing is about the harm and trust maltiez caused and broke. i have no little in the justification of why he did it or that it was successful. infact the idea that you would dedicate a significant portion of your official statement to justifying his actions and they fail to account for the collateral damage is staggering. three other discord communities that i participate in, that I didnt even know knew about this game have been calling it malwarestory for days. That sentiment cannot be cleaned with the malware author still employed. I cannot in good conscious tell them they are wrong while he remains. I WON'T tell them they are wrong while he remains. 6
Stellarbone Posted 2 hours ago Report Posted 2 hours ago 1 hour ago, HalfAxd said: Sorry, but no... you are not the community and you don't speak for me. If you don't like something, then you have the right to leave. At this point the rabble rousing is beyond absurd. Please say your peace and go. Never said I spoke for the whole community. Telling people who want things to get better to leave is a poor take. The rabble rousing is absurd, it never should have gotten this bad. Its piece. Say your piece and go. 1
kosan Posted 2 hours ago Report Posted 2 hours ago 34 minutes ago, Diff said: I could really reflect your request for half-reasonable claims here... These are not at all similar situations. NPM, PyPi, and Go are the exact same story as the ModDB. Entirely unreviewed. By anyone except the users. Go is especially egregious to include because it doesn't even have a centralized repository of any kind, you can upload to any public URL on the entire internet as long as it responds the way the Go expects. I think it's a special header or a query parameter or something. Linux distros are a closer analogy to this, and there are instances of maintainers going evil. But in the instances I'm aware of, they were trusted maintainers who didn't get their contributions reviewed at all, so we're back to being unreviewed here. We're not talking about the ModDB, which Maltiez is no longer present on. We're talking about the main VS codebase. Every line of code that gets submitted to VS gets reviewed by Tyron. These are flatly not the same situations, so yes, a one-person validation turns it into "no-chance" by virtue of it being a binary difference between "completely unreviewed" and "reviewed by a minimum of one person but sometimes more." How are you going to smuggle "accidentally" setting ClientMain to null past anyone with functioning eyes, let alone eyes that are scanning for multiple criteria? There is also the concern that the single person reviewing his code now has minimized the scope and impact of what was done - not once in the official statement was it outright stated that Anego considers distributing effectively malicious, hidden, obfuscated code as unacceptable, unprofessional, or otherwise a bad thing(tm) - instead it fully deflects the issue and weaves a story where the intent was to prevent cheating, and nobody else was affected (which is known to be false). The only thing I get from the statement is that the only problem here is that he was caught. So effectively, the fact that his code is reviewed before submission by someone who, as far as I can see, agrees with the sentiment that "the end justifies the means" is of no salvation to me. Further compounding my concerns about Maltiez in this situation is that, in my experience, modders that feel slighted by the community or other devs/modders have been known to escalate their retaliation, not reduce or reform. Especially when the person in question feels they were right, and did the right thing - regardless of what others think, which Maltiez has made clear a few times. 5
Diff Posted 1 hour ago Report Posted 1 hour ago (edited) I also wish the false positives had been mentioned. In truth, we don't know how widespread these false positives were. Mods are third-party code of unknown quality, and mods do just crash. Null Reference Exceptions in particular are the classic mystery meat crash, and they're the kind of crash that ConfigLib provoked. We do have at least one confirmed case of a mod caught in the crossfire, Caves N Caverns, due to it obfuscating its code. Speculating a touch, if CNC's 1000 downloads were enough to blow the lid off this, it does suggest that false positives were not common... But I feel that's the limit on how far you can reasonably minimize this issue. Ultimately, we don't know how widespread the false positives really were, and that itself is part of the problem. In a vacuum of information, a lot of crashes are now getting pinned on ConfigLib. Is it true? Were these crashes also mixed with random game inputs and disconnects, all consistently between 2-9 minutes after assets loaded? We don't know. Nobody that's claiming ConfigLib kicked their cat is going that far into depth with it. And the announcement only continues that vacuum of information. I'm personally fine overall with the VS team's current path forward, but that's the complaint I have with the announcement. Edited 1 hour ago by Diff 1
IAmMoss Posted 1 hour ago Report Posted 1 hour ago 2 hours ago, Stellarbone said: The cost of keeping Maltiez is the trust of the community. He's shown his hand, his only remorse was being caught. It's bad enough the dev team knew and Tyron didn't talk about any of the false flags or Maltiez's response in his official response, but keeping a lying ai techbro on the team is too much. AI tech bro? what is this in reference too? He has no access to the code. What he did was wrong, and his reactions to being caught are rather sanctimonious. That being said, As a Maltiez hater (as much as i like his mods, he's an ***hole), i feel he does not need to be fired. Reprimanded? banned from db? definitely. from what i've seen, he's just an advisor tho.
williams_482 Posted 1 hour ago Report Posted 1 hour ago 22 minutes ago, Diff said: I also wish the false positives had been mentioned. In truth, we don't know how widespread these false positives were. Mods are third-party code of unknown quality, and mods do just crash. Null Reference Exceptions in particular are the classic mystery meat crash, and they're the kind of crash that ConfigLib provoked. We do have at least one confirmed case of a mod caught in the crossfire, Caves N Caverns, due to it obfuscating its code. Speculating a touch, if CNC's 1000 downloads were enough to blow the lid off this, it does suggest that false positives were not common... But I feel that's the limit on how far you can reasonably minimize this issue. Ultimately, we don't know how widespread the false positives really were, and that itself is part of the problem. In a vacuum of information, a lot of crashes are now getting pinned on ConfigLib. Is it true? Were these crashes also mixed with random game inputs and disconnects, all consistently between 2-9 minutes after assets loaded? We don't know. Nobody that's claiming ConfigLib kicked their cat is going that far into depth with it. And the announcement only continues that vacuum of information. I'm personally fine overall with the VS team's current path forward, but that's the complaint I have with the announcement. This is what's bothering me. There's at least one highly upvoted comment in the reddit announcement blaming ConfigLib for crashes they allegedly spent hours debugging, but other users pointed out that the crashing behavior they described could not have been caused by ConfigLib. All we have to go on to understand the scope of the collateral damage here is guesswork based on a combination of crude statistics (very few downloads for confirmed conflicting mods, a long time between the malware going in and anyone connecting it to a legitimate mod crashing) and the host of people operating entirely on vibes, blaming ConfigLib for any crash they don't currently have a good explanation for. Some people erroneously blaming ConfigLib for crashes it didn't cause is totally unsurprising: mods causing crashes is a fairly common occurrence especially with the huge modlists many folks run with, and crashes are frustrating things that can be very difficult to debug. It's possible that ConfigLib actually did cause some real damage ("bricking" saves, for example) to innocent users, which would justify some of the vitriol flying around. My suspicion is that this alleged damage is being harped on specifically to justify the rage folks were already feeling, not because of any strong evidence that it happened, but I have no way to know for sure. 2
Diff Posted 47 minutes ago Report Posted 47 minutes ago 2 minutes ago, williams_482 said: It's possible that ConfigLib actually did cause some real damage ("bricking" saves, for example) to innocent users, which would justify some of the vitriol flying around. My suspicion is that this alleged damage is being harped on specifically to justify the rage folks were already feeling, not because of any strong evidence that it happened, but I have no way to know for sure. Hadn't seen that one floating around, but your gut feeling is right. To accidentally corrupt a save, just crash mid-save... But AdditionalStuff.cs only crashes in multiplayer games, where the client isn't the one handling saving at all. And the same line that bails out on single-player games also bails out if it's not running on the client side. No accidental save corruption should be possible.
A_British_Lass Posted 7 minutes ago Report Posted 7 minutes ago maltware retaining his employment after distributing malware and revelling in the fact is insane, anego do better 1
Recommended Posts