logo

Godot Engine Exploited to Spread Malware on Windows, macOS, Linux

ID: 4e3c0986-241c-5e67-a80e-6b4000b22e54

STIX ID: report--4e3c0986-241c-5e67-a80e-6b4000b22e54

Feed Name: HackRead

Threat Score
75/100

Date Published: 2024-11-29

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

GodLoader is a cross-platform malware loader that embeds malicious GDScript into Godot .pck game files to deliver payloads (notably RedLine stealer and XMRig), evading detection via sandbox/VM checks and Microsoft Defender exclusions; Check Point Research reports ~17,000 infected machines since June 2024 and warns up to 1.2M Godot users could be at risk, with distribution via many GitHub/Bitbucket repositories and advice to obtain software only from trusted sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.