Added thousands of addons

One user added thousands of addons at the same time.
https://ankiweb.net/shared/by-author/45871966

The user has reloaded the addons of other users. Because of this, not all addons are shown now with an empty query.

Too many matches found. Please refine your search.
7 Likes

Appreciate the heads up. I wouldn’t be surprised if they’re injecting malware. People suck sometimes.

9 Likes

Since June 2025, I have been collecting monthly datasets about addons (link).
At that moment, these addons were already unavailable in the addon list.

2 Likes

https://ankiweb.net/shared/by-author/890674635

The same thing, but so far only 35 addons.

3 Likes

This is malware. It downloads an executable from a random link and runs it on add-on startup.

@dae

6 Likes

VirusTotal analysis:

2 Likes

Maybe I need to give all those add-ons a low rating and warn users?

I don’t think you should bother with that. I’m sure it’s easier for us to round them all up at once.

The next time someone asks why we don’t have a page with the “newest” uploaded add-ons – this is the example we give them. It’s too much incentive for folks to publish garbage if they know it will get attention.

6 Likes

Well I only low rated an add-on that included my name. Though I think this is sufficient for now, if I gave a lot of low ratings could that cause any problems? (or is such action not recommended?)

e.g. if a large number of my add-ons are copied like this time I think I need to report them to the official Anki and then rating them low to avoid user confusion (because it would be troublesome if users mistake it for mine) but such actions look like trolling so I’m concerned that some kind of restriction might be imposed. (I have 100+ add-ons so the low ratings could 100+ at once.)

Those have been taken care of now too. Please just let us know if you find any more and we’ll get to them as soon as possible.

7 Likes

@dae
It seems to have been reposted.
https://ankiweb.net/shared/by-author/1874545439

Edit: It seems they have already been deleted, thank you.

6 Likes

@dae
This add-on code does not match the original and all 137 reviews are dated 10/5.
https://ankiweb.net/shared/info/1910833401

Edit01: this add-on is still prominently displayed and dangerous so I recommend giving it a low rating to lower its ranking.

Edit02: It’s already been deleted, thank you.

5 Likes

Also has the same malicious line of code.

1 Like

Thanks. I took this one down.

3 Likes

People reviewed negatively the original add-ons due to the copycat malware callout post

Bots mass downvoted the review hotmouse add-on

https://ankiweb.net/shared/info/1928346827

4 Likes

Are them bots? in order to make the original add-ons at the bottom, while the fakes one are getting upvoted?

1 Like

Yes, those were almost certainly automated by the threat actor in order to boost the rating of the malicious copies.

Can you batch-remove the ratings by these accounts @dae?

5 Likes

If I remember correctly many of those low ratings were already there before I posted, but the 2 most recent reviews might be because of my post, sould I delete or edit or repost that post?

1 Like

Sorry!

Its better to keep the post, are there more affected add-ons which got mass voted? It might be better to delete all the reviews from 2025-10-05, and keep an eye on previous days

2 Likes

So far I have not found any popular add-ons that suddenly received a large number of low ratings, if I find it I’ll post it.

2 Likes