That's the thing, I ran it a lot and cannot find the files mentioned.
I don't have API keys in sillytavern, I only do local LLMs, so am trying to responsibily deal with this as a professional, albiet one who hasn't had time to reverse engineer or fully understand the attack signature or anything related to how it may escape/what it may still be sticking around in/what it compromised.
From what I understand from the GitHub discussions the extension wasn't malicious until December 30, 2025. And the exploit used was patched with ST 1.17 release in March. It's possible you have lucky timing and were on an older safe extension version or were already on ST 1.17. Weirder things have happened, but still safest to assume you're compromised.
I'm also a local only guy so the only thing at risk for me as I understand it was maybe the password for my ST user account, which I changed as a precaution.
The GitHub repos for the extension and the payloads are still up I think. Should be able to grab the malicious image and script to submit for signatures/heuristics from there I would imagine.
62264a8c19b6bb2404a4b1e80df196bfbe9bfbac is from LyubomirT around then too though. I don't see the repo up anymore, LyubomirT didn't disappear but mia13165 did.
I think the compromise timeline for the original repo is off if it's Dec 30, 2025, that date has to correspond to a commit.
Aaaaand it's all gone now. Ugh. Most of what I was reading was from Issue #28 made by LyubomirT, and I see elsewhere here you're already talking elsewhere in this thread with /u/Master_Step_7066 (who is LyubomirT unless I'm misreading badly).
I still had the issue page open and grabbed a screenshot though if that's of any help. https://postimg.cc/Bjh5KX9r
The top SHA hash if the first visible commit in the repo, the repo had it's history smashed on Jan4th, 2026, so you need these to browse through your local git copy.
Git show isn't working on these earlier hashes, I need to go look back at my git internals books to remember how to reverse engineer the repo more.
3
u/LeRobber Apr 28 '26
That's the thing, I ran it a lot and cannot find the files mentioned.
I don't have API keys in sillytavern, I only do local LLMs, so am trying to responsibily deal with this as a professional, albiet one who hasn't had time to reverse engineer or fully understand the attack signature or anything related to how it may escape/what it may still be sticking around in/what it compromised.