More than one infected client
My friends and I all came back to play realm again for MotMG, and we downloaded the 28.0.0 client posted by user '001.' and then when the game updated we all got the 059 client for the hotfix patch.
As some of you may already know a list of the compromised accounts were compiled into various pastebins and spreadsheets which I have looked through. There was a pastebin released roughly 16 hours ago that had around 3k names listed on it (mine being one of them) and a lot of those players are being hacked and killed off currently or already were.
This was thought to be from a single client, the CC client which fixed the pet yard. The fact that my 2 friends and I all never used that client or even downloaded it is proof that there was at least one more client posted here which was malicious.
Now like I said above the first released list of names was released on pastebin roughly 16 hours ago and the two clients I have used since this all began were the 28.0.0 client by user '001.' which was posted roughly 2 days ago now, and then the updated one for the hotfix by 059 which was released 14 hours ago. This makes me think that definitely the malicious client out of the two was the 28.0.0 client by 001..
This list has been updated and another 1k+ names have been added to the list where you can see all of the account names linked to realmeye that have been compromised. This list updated roughly 2 hours ago now, this means that they are still compiling account info from the users who used the malicious client and more people are still going to be at risk if you haven't changed your password since you last logged onto the 28.0.0 client by 001. which is the second client which I strongly believe to be infected.
They had my name on the original list of names released and my account only got hit an hour ago after having the information for 16 hours. I also checked the names around mine on the list to see if they were hitting accounts alphabetically or not throughout this list and they are not as far as I can tell.
From what I can see so far there really is no pattern to how they are hitting the accounts named on this list and it seems highly random, possibly only prioritizing accounts with the summer solstice items such as the stave/spell as I had several spells, the ring, and staff and those were all taken. No way to tell for sure though, and it seems largely random.
pastebin . c0m/Wn3k8x7E is the link to the updated list, Ctrl + F for your name and if it pops up I would certainly change your password again immediately and delete all current clients you have downloaded just in case until all of this blows over and we are confident that clients posted here can be trusted again. If you used the 001. client, I highly recommend changing your account info immediately as well even if you don't see your name on the list as it's obvious they are still updating and compiling info.