⚠️ Security warning for MakerWorld / 3D printing community
I’ve found several recent model uploads containing malware disguised as a “3D File Preparation Tool”.
The downloads typically contain:
• ZIP inside another ZIP
• a .blend file
• an executable called 3D File Preparation Tool.exe
• an AutoHotkey script
• instructions claiming it converts models
There are no STL or 3MF files included.
Inspection of the script shows it extracts a hidden payload from the .blend file, runs PowerShell with execution policy bypass, launches a bundled Blender executable with auto-exec enabled, and then drops another file disguised as a converted model.
In short: it’s very likely malware targeting 3D printing users.
If you see downloads like this:
❌ Do NOT run the EXE
❌ Do NOT run the tool
❌ Delete the files
Only download models that include normal formats like STL or 3MF.
I’ve reported this to MakerWorld, but please spread the word so people don’t accidentally run these files.
Videos
Why is makerworld.com considered safe?
Is makerworld.com legit or a scam?
Is makerworld.com reliable for online purchases?
Is makerworldxa safe site to download files from? I'm nervous about downloading from Strange sites.
Link to original post: https://mastodon.social/@3dprinty/111282007082869900
Nach Printables hat es jetzt Makerworld erwischt: es tauchen wohl vermehrt "Modelle" auf, die vorgeben, irgend eine Artt von Umwandlungstool zu sein und eine .blend Datei für Blender, eine Exe und ein Aurohotkey Script enthalten (warum auch immer ausgerechnet Aurohotkey). Das Ausführen der .exe öffnet dann Blender und tut so, als würde es irgendwas konvertieren, in Wahrheit lädt aber ein Script, das seltsame Daten von irgendwo besorgt und am Admin-Dialog vorbei ausführt.
Deswegen die Warnung: führt nichts aus, was von Makerworld kommt. Wenn in einem Download nicht ausschließlich stl, 3mf und vielleicht noch eine ReadMe sind, sondern Skripte und ausführbare Dateien: sofort Finger weg und melden!
⚠️ Security warning for MakerWorld / 3D printing community
I’ve found several recent model uploads containing malware disguised as a “3D File Preparation Tool”.
The downloads typically contain:
• ZIP inside another ZIP
• a .blend file
• an executable called 3D File Preparation Tool.exe
• an AutoHotkey script
• instructions claiming it converts models
There are no STL or 3MF files included.
Inspection of the script shows it extracts a hidden payload from the .blend file, runs PowerShell with execution policy bypass, launches a bundled Blender executable with auto-exec enabled, and then drops another file disguised as a converted model.
In short: it’s very likely malware targeting 3D printing users.
If you see downloads like this:
❌ Do NOT run the EXE
❌ Do NOT run the tool
❌ Delete the files
Only download models that include normal formats like STL or 3MF.
I’ve reported this to MakerWorld, but please spread the word so people don’t accidentally run these files.
I made a simple model a year ago, it was simple but very functional and nothing really existed in that way and shape. I thought it was a nice idea and since Makerworld provided some protection and commercial license (explicitly when you upload a model) I thought why not. Got some thousand downloads in 1 year. All of a sudden I get messaged by a friend which also is an author on the platform, saying that my model had been copied entirely. And it really was, literally the same model with 1 miniscule change (1 sloped surface). And it instantly got almost a thousand downloads. Contacted makerworld 3 times, they told me they don't see any problem with it. Contacted the author, told me he did basically reverse engineer my model. Also told me "I've also been copied" and that's how it works on Makerworld.
I don't really need the points but didn't Bambu just release the exclusive model initiative to protect novel ideas on Makerworld? Isn't this the whole point of the new approach?
Honestly we don't really feel like uploading novel ideas anymore, if this is what happens afterwards. Actually this just seems like I would benefit from doing the same as he did to get points, buy filament and then use my novel ideas on other platforms.
Has any of you encountered the same problem? Do you feel protected as authors?
EDIT:
Thank you all for answering. I guess you’re right, I’ve been naive on this argument probably. I don’t really want to endanger neither his nor my profile, also don’t really care about specifics, so I won’t disclose the models. Just wanted to know your opinion and approach. I guess as some of you suggested I’ll keep the good ideas out of the platform and play this game to get the points. Still sad to see honestly.