Is Shaders.zip safe?
Zero engine detections but community YARA rules and researcher comments flag credential-stealing behaviour.
Seventy-five engines returned clean results, yet YARAify matched eleven rules and two researchers describe Roblox account theft via a multiplay.at C2 endpoint. The file is a Chrome extension distributed to 170 submitters in the last month.
81eb1139b76c2630e7…b658c5399c622aRecommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Seventy-five engines returned clean results, yet YARAify matched eleven rules and two researchers describe Roblox account theft via a multiplay.at C2 endpoint. The file is a Chrome extension distributed to 170 submitters in the last month.
The complete absence of malicious engine detections across 75 scanners is a strong clean signal. However, YARAify’s eleven rule hits and the two researcher comments that explicitly describe credential theft and a live C2 domain create a direct contradiction. Because the extension is only 29 days old and the contacted-host reputation check is missing, the evidence is mixed rather than decisive.
What We Detected
Zero malicious detections from 75 engines; 17 tier-1 engines explicitly marked the file clean. YARAify matched eleven community rules, five of which fired in our heuristics (Any_SU_Domain, Detect_Golang_Binary, Detect_PowerShell_Obfuscation, DetectEncryptedVariants, Discord_APIs). Two researcher comments describe Roblox session stealing, cookie exfiltration, and a C2 endpoint at multiplay.at.
Threat Behavior
Static evidence and researcher reports indicate the extension activates only in developer mode, contacts a remote API to validate cookies, and harvests tokens from Roblox, Spotify, Netflix, Twitch, and Twitter/X. No sandbox execution data or host-reputation results are available to confirm or refute these claims.
What To Do Now
Do not load the extension. Keep browser protections enabled. If already installed, remove it via chrome://extensions and change passwords for any services whose cookies may have been exposed.
Where this verdict could be wrong1 caveat
- YARAify rules include generic patterns (Detect_Golang_Binary, Detect_PowerShell_Obfuscation) that may match legitimate tooling.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 engines flagged malicious
- 17 tier-1 engines marked clean
- Widely submitted (170 sources)
- YARAify community rules triggered
- Researcher comments describe credential theft
- C2 domain referenced in comments
- Extension requires developer mode
Treat the extension as high-risk; do not install or retain it until independent sandbox confirmation is available.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete5 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 5rule hits recorded
- 0 / 75engines flagged
- 170sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
5 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceObservedSourceSignature and behavior rulesObserved at - 02
0 of 75 antivirus engines flagged the file.
ProvenanceObservedSourceAntivirus analysisObserved at - 03
YARAify matched 11 researcher rules to this file.
ProvenanceDerivedSourceSaved report factsObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- Any_SU_Domain
- Detect_Golang_Binary
- Detect_PowerShell_Obfuscation
- DetectEncryptedVariants
- Discord_APIs
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.
Fingerprint and provenance
- File name
- Shaders.zip
- Format
- Google Chrome Extension
- Code signing
- Not applicable to this file type
- Size
- 551.7 KB
- Last analyzed
- Sep 7, 2026, 4:46 AM UTC
81eb1139b76c2630e76c14a867abc81a92e5670cfbd82714aab658c5399c622aSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Shaders.zip safe, or is it malware?
What is Shaders.zip?
How many antivirus engines detected Shaders.zip?
What should I do if I already opened or extracted Shaders.zip?
How do I remove Shaders.zip?
What is the SHA-256 hash of Shaders.zip?
How up to date is this analysis of Shaders.zip?
Community
Member reviews and reports for this exact file hash.