Skip to main content
BluWizard
Lead Docs Author, Community Helper, Shader Contributor
View all authors

Poiyomi Shaders 10.0 out now!

· 19 min read
BluWizard
Lead Docs Author, Community Helper, Shader Contributor
Poiyomi
Creator, Shader Developer

After several months of testing and development, we are very excited to welcome Poiyomi Shaders 10.0, our biggest update since the first ever release of Poiyomi Shaders! 10.0 marks a brand new chapter in our overall development cycle.

We have so much to talk about! There's a lot of new features, added improvements to the overall experience in Unity, and a wide assortment of bug fixes. Watch the video attached below to listen in and see all the changes we have made. Otherwise, refer to our Official Changelog for the most detailed list of changes you can expect to see (although it's a VERY LONG post!).

Legacy Shaders Removed

As of this release, versions 7.3, 8.0, 8.1, 9.0, 9.1, and 9.2 have been officially deprecated and no longer exist in this release! This was done to cut down on file size. If you are still using any of these versions mentioned above, PLEASE UPGRADE NOW!!!

Our improved translation utilities have been updated to make this transition as seamless as possible. Any materials detected to use an older version will prompt you to translate them to 9.3. This allows you to choose when to translate your materials to 10.0 at your own convenience.

Be advised, our translation pipeline heavily relies on serialized material GUIDs. For this reason, please ensure you are up-to-date to 9.3. Additionally, make a back up of your materials!

A whole UI overhaul!​

The whole UI has received a broad modernized refresh across all sections of the shader.=

Immediately, you will see more compact areas, heavily reduced white spacing, better DPI scaling on headers, and many new decorative elements.

Every single section across the shader have been reorganized to fit the new UI changes. If you don't see a feature that you saw before, don't worry! Material properties remain the same, with only UI-facing changes in it's labeling and it's organization in the UI.

Most notably, some features that come from LilToon now closely match their UI, such as Backlight and Lil Reflections.

You will also see more Helpboxes across the UI. We have began using these in areas that are appropriate. For example, if you attempt to use Back Face feature, it will now warn you if you forget to turn off Culling, which is required for that feature to function.

Additionally, in some sections where the effect needs a Depth Buffer, you will see a new Prefab spawner button that will add the required DepthGet Prefab into the Scene for the shader effect to work.

Upgrade & Translation Pipeline​

We have some exciting news to share regarding the process of upgrading to 10.0!

To start, we have overhauled our scripting pipelines to account for both previous and legacy versions of Poiyomi. This means the process of upgrading from 9.3 (or an even older version) straight to 10.0 can be done with minimal to no visual differences!

You have 3 different ways to upgrade your materials...

  1. Use our new Material Upgrade Utility (Recommended). This allows you to do a mass-upgrade of materials on your Avatar to the latest 10.0 version, running each material through our translation pipeline, all at once!
  2. Right-Click on a Material as before, and click Poiyomi -> Materials -> Update Poiyomi Shaders.
  3. Or just swap the shader from the dropdown! Translations now run automatically when moving from an older version to a newer version. If you don't like it, you can turn it off by toggling Poi -> Auto-Translate Materials On Shader Change in the menu bar.

Alongside this, I have been working to account for a variety of configurations. I may not cover all setups, but the baseline is there to help you have a smooth transition. This means if you happen to have had a serialized material (or locked one) that's on a much older version like 8.0, we have added parameters to make sure those are translated smoothly as well. This does have a limitation, however! It relies on GUIDs and original shader name references. So if you want to make sure you are good and damn ready to upgrade, please consider updating your materials to 9.3 first!

Grab Pass Users, Heads Up!

Grab Pass received a large overhaul in this update to make way for the Pro-exclusive Lava Lamp feature, which will be detailed here and in the Changelog. Due to the changes received, much of your appearance settings will not translate accurately.

For this reason, we highly recommend you back up your Grab Pass materials before jumping to 10.0!

Lastly, I've also added more translation parameters for our LilToon pipeline as well. Switching from LilToon 2.3 to Poiyomi 10.0 should be much smoother now!

New APIs​

To compliment our newly overhauled translation pipeline, we have added new developer-accessible API endpoints to the C# namespace Poi.Tools.ShaderTranslator.VersionUpgrade to allow developers to use our upgrade pipelines to how they see fit. For more information on how to use these APIs, refer to our Upgrading Documentation.

New Features​

Theres a TON of changes in this release! I won't be able to cover all of them here as the changes are just that gigantic. So, I'll cover some of the headlining features you'll notice right away.

  • Dissolve has been rewritten with new features, including a full UI overhaul, more advanced configuration options, and a wide arrangement of new effects are now possible.
    • Use Alpha Only to ignore the Alpha, used for dissolving only the Alpha, our most common usage case.
    • Edge now supports a gradient of two colors.
    • Wave Mode allows the effect to dissolve in a wavy pattern.
    • Added support for outputting the Dissolve effect to a Global Mask
    • And added vertex manipulation with the Dissolve.
  • We've added Chromatize and Tint to Color Adjust to change the intensity of the color's reproduction and quality on how the perceived hue can be affected.
  • OKLab was added to Global Themes, with backwards-compatible legacy values.
  • Each Decal now has their own independent set of Color Adjust settings.
  • Added a Flashing blinking pattern to Emissions.
  • Exposed Alpha to Emissions, which means Alpha can now control the intensity.
  • Added Highlight to Outlines, including Audio Link support for it.
    • This is the exact same function found in LilToon.
  • Outlines now coincide with our modern Color Adjust framework, with backwards-compatible legacy values.
  • You can now set RGBA Color Masking, Decals, and Matcaps to show on Outlines if you want. Enable via a new toggle Show on Outlines, located in their respective sections.
  • In AL Spectrum, we've added new appearance options including UV mirroring, bilateral mode, band range, and improved positioning controls.
  • We've added support for VRC Light Volumes 3.0, and placed Intensity, Shadow, and Normal Bias configuration for Light Volumes within the Light Data module for finer control.
  • We've added Skin, a new experimental LUT coloring module allowing users to apply Skin coloring to the Base Color.
  • Added Bent Normals, which allow specular occlusion and indirect diffuse to affect your appearance.
  • Added Light Falloff an Attenuation curves to compensate for brightness at a distance.
  • Added a Normal Map 2.
    • Why? Because we found most people don't know that Details can act as a second Normal Map. So, here you go. Enjoy.
  • Added Global UV Configuration, which allows you to share consistent UV configuration across all modules.
  • Video Effects can now affect Decals and have Global Masking support. Enabled by turning on Apply Video Effects in Decals.
  • Grab Pass now allows masking, color ramp effects, pixelation effect, bounding circle blur, precomputed Gaussian kernel, and output clamping.
  • Stylized Specular had it's Lil Reflections mode reworked and now supports Tiling, Offset, Panning and UV adjustments.
  • LilFur now supports ALL modules in Poiyomi Shaders, including Emission, Proximity Color, UV Tile Discard, Audio Link, Dissolve, and more!
    • To add to this, LilFur UVs are no longer tied to the main UVs and can be assigned per-texture UV.
    • We've also added a Wind Effect, which is kinda neat!
  • We now support VRChat's Shader Globals for time-synced animations, on by default.
  • Constellation now supports random colors, improved star movement speed, and better Audio Link controls.
  • Proximity Color can now override Emission, check it's influence on the Alpha, and more.
  • We overhauled Glitter with new randomized rotation direction, sprite sheet support, and linear controls.
  • Internal Parallax now supports Global Masks, distance falloff, pan offset, and now behaves more like Decals.
  • Matcaps can now act as a fallback cubemap by using the Reflection Fallback toggle.
  • Backlight now supports Global Masking.
  • And added support for Unity 6, ready for whenever VRChat is ready to unleash their SDK for Unity 6.

New Features in Pro-only Versions​

Many of these have already been seen by our Patreon subscribers, but we might as well notate them here as a refresher for our Poiyomi Pro subscribers! If you want to try these effects out for yourself, subscribe to use via Patreon here: patreon.com/c/poiyomi

  • Added Contact Shadows, a screen-space shadowing system.
  • Added Lava Lamp to Grab Pass, a really cool raymarching effect that simulates the physics of a real Lava Lamp.
  • Added Squish, a Vertex-based deformation effect with falloff, color gradient mixing, masking, and supports SPS Sockets.
  • Added Triplanar Projection shader, enabling the ability to use world-space triplanar texturing with edge fading, distance fading, depth clipping, self-mapping, and exposed depth sampling accuracy.
  • Added Self Grab, an experimental Grab Pass effect that uses an outline-like effect to affect Grab Pass onto one's self.

Lighting​

Poiyomi 10.0 has introduced a ginormous amount of lighting changes. There's a lot of technical details that I won't mention as most folks watching this may not understand what I'm talking about, so I'll refer to the exact details in the changelogs.

Regardless, many of these changes you will not notice for the most part. So if anything, you will barely see a difference.

However, let's talk about some obvious details you will see!

  • We have decided to rename Shading > Shading into Shading > Shadows to avoid confusion. And to be honest, it makes sense! We will now be referring "Shading" as to "Shadows" for the entirety of this post, so pay attention!
  • Realistic Shadows mode now has a Shadow Strength slider since it didn't have one. Additionally, Realistic now finally uses Unity's dielectrics for the default BRDF.
  • Multilayer Math now uses the main shadow as the main attenuation, with each layer using it's own attenuation. This means the shadows are made to be more subtle.
  • Cloth now uses precalculated indirect color.
  • We have adjusted the Min Brightness behavior with a noise floor and a new minimum light cap.
  • The Max Light count has been lowered, fixing the light loop break as a result.
  • And turning off Shadows no longer breaks modules that don't use the lighting loop.

Modular Shader System​

Shader developers, this one's for you!

We are excited to announce that the Modular Shader System, the system that we have used to build Poiyomi Shaders since 8.0, is now fully available to the public! With this, you can now easily install your own modules within the shader using our toolset.

By default, we expose only the Free features in the official public release, while the Pro-only features remain locked away in the Pro-only release.

To learn more about how to develop Modular Shader templates, refer to our documentation here.

Changes & Fixes​

Over the course of developing 10.0, it was an opportunity for us to address some long-standing issues and squash as many bugs as possible. These are just some of the bug fixes you will be happy to hear about (see more in the full changelog).

  • Emission Theme Color now replaces the Emission Color instead of multiplying it. Emission Color also tints into the Theme Color.
  • Matcaps now default to Replace blend mode.
  • Matcap Border now defaults to 0.5.
    • If using Double Sided mode, set the Border to 0.43 for the intended appearance.
  • Multilayer Math default settings are now updated to match LilToon 2.3.
  • Decals are now rendered before Matcaps.
  • Grab Pass functions are now moved to render in front of Decals and Matcaps.
  • Hue Shift moved after saturation in Global Themes.
  • Default Fur Noise no longer generates mipmaps (otherwise, fur was losing detail at a distance). Smoother fur LOD.
  • LilFur default noise textures corrected to use Linear instead of sRGB, matching LilToon's upstream repository.
  • AO is now applied to the main light and Occlusion is applied to the indirect color.
  • Fixed Latex Matcaps having JPEG artifacts.
    • Latex lovers, rejoice!
  • All included textures using Mipmapping now set to use Kaiser filtering, fully supporting VRChat's DPID filtering algorithm.
  • "lilToon" or "lil toon" is now referred as to "LilToon" for general professional appearance in references areas in the UI.
  • Fixed dynamic_branch fog and variant strippers in Unity 2022.3.
  • Fixed vertexSH, UIElements fixed, ui: changed to uie:, ifdef guards for LOD crossfade.
  • Fixed .NET API compatibility and replaced deprecated/obsolete editor methods.
  • Fixed Unity's corruption of namespaces in various scripts.
  • Fixed Panosphere UV stereo offset.
    • MonoPanoProjection had an eye-dependent Y offset that was being scaled by texture tiling, producing different visual positions per eye with any tiling (especially on Decals, Main Texture, etc.). Mono mode now returns identical UVs for both eyes. StereoPanoProjection keeps eye-dependent behavior for real over-under stereo content.
  • Fixed Panosphere perspective-correct.
  • Fixed camera position inside mirrors.
  • Fixed LilFur visibility bugs in the Mirror/Camera module.
  • Fixed lots of stereo rendering, mirror, and VR-related issues.
  • The Shader Optimizer now wipes out orphaned textures, saving greatly on VRAM.
  • Fixed locking on several modules over the course of development.
  • Subsurface Scattering now behaves the same when locked.
  • Fixed Min Brightness ringing on indirect color.
  • Fixed some lighting mistakes on Realistic Shadows mode.
  • Fixed add lights double-counting attenuation and add light shadows no longer skipped.
  • Fixed spot light support, light clipping, double-add on point/spot lights, and add light contribution in Subsurface Scattering.
  • Fixed ordering of Matcap, Rim Lighting, Depth Rim Lighting, and Cubemap.
  • Fixed Environment Reflection issues while Rim Lighting was enabled.
  • Fixed unassigned referenced Metallic map and fixed texture sampling calling the wrong function in Cloth shadows mode.
  • Fixed Theme Color in AL Spectrum double-multiplying and blend types using Range(0, 1) instead of Int.
  • Fixed Global Themes causing potential NaN at high Saturation and Brightness values.
    • As a side effect, there may be some limits added to prevent over-exposure issues (which look bad on cameras).
  • Fixed Decal 3 having an extra Z field even though it's unused.
  • Fixed mixing Metallics with other modules, as well as masks, anisotropy, and undeclared identifier / redefinition errors fixed.
  • Fixed Lil Reflections in Stylized Specular not rendering correctly.
  • Post Processing now works with Emission and Decals, and with the Add Pass and LilFur.
  • Fixed Render Queues not transferring when upgrading/translating materials.
  • Fixed some Z-fighting issues when exposed to projection shaders.
    • There are only mitigations to prevent it from happing. If you still see it occurring, please let us know!
  • Fixed Ignore Fog function.
  • Fixed Global Mask label indentation, text alignment, and animated property marker vertical alignment.
  • Fixed a LilToon translator write-priming bug causing every write to be primed with a throwaway value first due to a StringComparison bug.
  • Fixed Decal enum mis-mappings in LilToon's translation, and && guard replaced with || guard on HSVG in Outlines. Some corrections from LilToon's sneaky UI tricks.
  • Fixed an issue where cross-edition (Toon <-> Pro) upgrades got borked.
  • Legacy Material Detection and translation scripts improved twice, now using Poi.Tools.ShaderTranslator.VersionUpgrade APIs.
  • Fixed Rim Lighting translation issues from 9.3 to 10.0.
  • Default ShaderDestinations updated for 10.0.
  • Fixed various Decal Positioning Raycaster functionality issues.
  • Fixed Grab Pass preset dropdown being drawn without a label.
  • Fixed GIF support by merging without a System.Drawing dependency.
  • Fixed Receive Casted Shadows not being set to 1 on PBR presets.
  • And an assortment of typos and spelling fixes!

ThryEditor​

Our most advanced material inspector interface, ThryEditor, has received a huge amount of updates.

To start off, we have forked it!

What does this mean? Well, basically, we now maintain ThryEditor on our own and many changes are way ahead of the original repository. From this point on, we now will be using poiyomi/ThryEditor on GitHub, instead of Thryrallo/ThryEditor. Because ThryEditor was graciously licensed under MIT, that has allowed us to maintain it on our own and be able to make changes quickly and effectively.

Additionally, ThryEditor will now be supplied as a VCC Package! This is already included in our main Poiyomi Shaders repository and will be auto-installed via VPM when installing 10.0 for the first time. By doing so, we can quickly fix editor-related issues without having to update the whole shader package anymore. This change does not affect the Poiyomi Pro version or .unitypackage versions.

Not only that, but having ThryEditor as a VCC Package will allow other Shader Developers to use it without having to install Poiyomi Shaders at the same time, if they wish to use it.

Alongside that, a lot of New Features have been added to ThryEditor, such as...

  • Global Linking, our replacement to Material Linking. Follows the same principles as Material Linking, but now linked together as a global json value, making it easier to quickly link up materials together without relying on one material as a source of truth.
  • Blueprints, allowing users to generate materials with a pre-determined set of Presets applied. Useful for creators who want things done quickly.
  • Refreshed the Material Lock Manager with a new toolbar for Grouping and Filtering results straight from the UI.
  • Added a Clear button for inline RGBA packers.
  • Added a "dot" indicator on Headers, which will indicate if properties contained are tagged as A or RA.
  • Many new properties, sliders, and decorators for the shader UI such as Headers, Descriptors, improved Helpboxes, and many more surprises!

Additionally, our Shader Optimizer system now sorts Locked Shader files into Assets/_LockedShaderCache. This allows us to cache compiled variants and ensure locked samplers can be shared across materials where possible. As a side effect, Unlocking no longer deletes cache-resident shaders, making Unlocking twice as fast than before.

We've also Fixed the following issues...

  • Fixed VRCFallback tags not being carried over on upgraded materials.
  • Fixed handling of Rendering Presets.
  • Fixed some headers unable to be marked as animated.
  • Fixed an issue where the list and GUI are computed every frame in the Material Lock Manager. It is now computed one per rebuild, saving greatly on CPU.
  • Fixed an issue where script compiling triggered a full project re-scan in the Material Lock Manager.
  • Fixed Inspector Rebuild occurring often in some usage scenarios, especially during Lock/Unlock.
  • Fixed multiple ShaderProperty name collision bugs.
  • The GuessShader levenshtein sweep no longer run constantly and is only executed when absolutely needed.
  • Fixed a NullReferenceException on the Render Queue property when Right-Clicked.
  • Fixed a nasty null element found when running PropertyValueAction, which mainly affected legacy shaders.
  • Fixed some GUI issues if for some reason Thry Editor is being used on very... very old legacy shaders (what are you doing?).
  • Fixed an old regression causing Render Queues to show incorrect readings on custom values.
  • And replaced some dead URLs from prompts and menu items with up-to-date ones.

Removed​

In case you didn't see the bright red warning above, I'll show it to you again here...

Legacy Shaders Removed

As of this release, versions 7.3, 8.0, 8.1, 9.0, 9.1, and 9.2 have been officially deprecated and no longer exist in this release! This was done to cut down on file size. If you are still using any of these versions mentioned above, PLEASE UPGRADE NOW!!!

Our improved translation utilities have been updated to make this transition as seamless as possible. Any materials detected to use an older version will prompt you to translate them to 9.3. This allows you to choose when to translate your materials to 10.0 at your own convenience.

And this is VERY IMPORTANT! When you upgrade to this release, your legacy materials must be translated to 9.3. This is our conservative approach to ensure nothing breaks at first, giving you the choice to translate the material to 10.0 whenever you feel comfortable to do so.

To ensure you have the most minimal amount of issues, please make a backup! While we have systems in place (as mentioned above) to ensure older versions can be translated with the old shader files removed, it only works reliably if the materials were properly serialized with their original GUIDs! In case they weren't serialized, PLEASE make a back up of your materials!

And finally, please be prepared for the following items that have been officially deprecated as of 10.0:

  • Removed Raliv DPS integration.
  • Removed Shadow Tint from Realistic Shadows (replaced by Shadow Strength).
  • Removed unused module collections.
  • Removed dead scripts.

Conclusion​

That pretty much covers the headlining features. For those tech-savvy creators who want all the spicy details, they are all documented in our changelog. Be advised it's a 25 minute read, hence why I didn't mention everything here. You can find the full changelog here.

A big special thanks to our Patreon subscribers for for helping us iron out all the issues in Poiyomi Pro 10.0 while this was in development. If you want to be the first to try out new and experimental features before anyone else, be sure to subscribe for $10/month on Patreon. No pressure though!

Lastly, a big thanks to our active Discord team members for assisting our users with questions and answers. Y'all rock!

Thank you for reading and I hope you enjoy using Poiyomi Toon 10.0!

Getting Hacked, How it Happened, and How to Protect Yourself

· 13 min read
BluWizard
Lead Docs Author, Community Helper, Shader Contributor

Hello everyone, BluWizard here.

I'm happy to announce that things are starting to return to normal here at Poiyomi Labs. The malicious actor responsible for the hijacking has been properly dealt with, disposed of, and thrown in the Garbage Compactor.

Clear your Browser's Data!

It is highly recommended that you clear your browser's cookies and data before accessing pro.poiyomi.com to download Pro Shader packages.

This is because we've received some reports that existing cookies will throw an error when attempting to download it through the Pro VCC Package.

Wait... what happened?​

In case you have been living under a rock this whole time, a cybersecurity event occurred on Poiyomi's accounts. If you don't know who Poiyomi is... then I am very shocked.

Duh! He's the creator of Poiyomi Shaders for god sake! The one who created the shaders for our Avatars in VRChat that we know and love today!

But, how did this cyber attack happen? Well today, I am going to break down what exactly happened based on the information I've learned and from my research into this incident.

This is going to be a much different subject than what we normally talk about here, so sit down and drink some coffee because this one is a doozy!

The Attack​

On April 13th, 2026, Poiyomi fell victim to a targeted cyber attack that involved a takeover of their Google Account and Discord, among others. During that time, packages were temporarily inaccessible and voluntarily taken down as a security precaution.

To put things simply, Poiyomi, like all of us, are gamers. And just like anyone, we can fall for security exploits that happen without us even noticing. His account got compromised after downloading a modpack for Minecraft from CurseForge.1 The attacker invited Poiyomi to a Minecraft server over Discord and provided a package to install via CurseForge, which is a known reputable website across the Minecraft community for hosting user-generated modpacks for Minecraft. Not only that, but the attacker used social engineering by digging into their friends list to claim that people they knew were already playing Minecraft in order to draw them in.2

Once the Modpack was successfully installed via CurseForge, chaos ensued.

The hacker gained control of Poiyomi's Google and Discord account via session hijacking. This is known as a "token grab," which is a malicious scripting attack where the login token is stolen from the browser's cookies and sent over the internet. This is a known social engineering attack layered on top of a technical one, where the attacker used a trusted social context to lower the victim's guard before deploying malware.

Once the attackers had access, they quickly snooped over his personal information leading to possible identity theft due to the sheer amount of personal information linked to their Google Account.

Now, you may be asking, "Wouldn't Poiyomi use Multi-Factor Authentication (2FA) everywhere?"

Yes, you would be right. He did have Multi-Factor Authentication enabled. Except that, even if you have Multi-Factor Authentication enabled, your login tokens are still exposed as a cookie!

The Malware Vector​

This is not the first time CurseForge was weaponized this way to attack video gamers. A known variant of this exact incident dates back to Fractureiser in 2023, where several CurseForge and Bukkit accounts were compromised and used to inject malicious code into plugins and mods, which were then adopted by popular modpacks such as Better Minecraft, which amassed over 4.6 million downloads. Notably, many of the impacted modpacks were compromised regardless if the owners had Multi-Factor Authentication or not.3

The malware's purpose was to act as an infostealer — which stole Minecraft and Discord authentication tokens, as well as cookies stored on the web browser.4 This is the exact kind of malware Poiyomi fell victim to.

Another instance of this malware vector was the Stargazers Ghost Network which distributed malicious loaders disguised as legitimate Minecraft mods through over 500 GitHub repositories, boosted with fake stars and forks to appear trustworthy. Once installed, the malware captured Minecraft session tokens, Discord and Telegram login tokens, and deployed a .NET-based stealer to exfiltrate browser passwords, VPN logins, and other sensitive information.5

These vectors have one thing in common — they use the same Java-based architecture to hide malware inside .jar files that is executed silently alongside the game.

How Session Token Theft Works (and Why Multi-Factor Authentication Can't Stop It)​

When you successfully log in to a web application, the server generates a session token stored as a cookie in your browser. This token tells the server, "I have already proven who I am, so keep me logged in." Unlike credential theft, which targets usernames and passwords, attackers can abuse the token created after authentication — directly bypassing the need to know a password.6

Why doesn't MFA help once a token is stolen? Well, that's easy. Multi-Factor Authentication only serves one purpose: Guard the Login. Once the Login is complete and a session token is issued, Multi-Factor Authentication has done it's job. Now that the session is valid, it can remain active for hours or even days by assuming the Web Browser's cookies were never cleared regularly. So when an attacker steals your token, no login event is triggered and no Multi-Factor prompt is triggered because the Multi-Factor Authentication already happened when the original session was created.7

All modern Web Browsers store cookies in databases on the user's device. Malware specifically designed to target these databases can silently extract session tokens and transmit them to attackers, which is done through infostealer software. The same infostealer software is often used to "pass-the-cookie" which occurs when attackers hijack a victim's session cookies even when the application is not being used.8 Because of how session hijacking bypasses Multi-Factor Authentication and passwords entirely, it is one of the fastest-growing attack vectors across the internet. If you think about how large this can be scaled, it is pretty frightening.

What We Did​

Shortly after the attack occurred on Poiyomi, his Discord account began to act maliciously... changing permissions and removing Moderators since Poiyomi's Discord Account was the Server Owner (which has ALL permissions). The entire team here at Poiyomi Labs worked their very hardest to suppress the malicious actor's actions (which was hard to do because the malicious actor had access to a Server Owner's account).

To further protect ourselves, we began voluntarily shutting down our VCC Repositories, suspended Poiyomi's GitHub accounts, and began recovery efforts as soon as possible. It didn't take long for Poiyomi's Patreon account to get accessed by the malicious actor. Due to Patreon's extremely poor customer service, recovering access to their account was a nightmare. Eventually, Poiyomi regained access after the entire community yelled at Patreon on Twitter/X on the issue.

Funny enough, Patreon decided to discontinue customer support on Twitter/X shortly after this incident became widespread on the platform. Coincidence? I think not!

What followed for an entire week was a tireless effort to recover ourselves from this incident. A lot of misinformation was spread about "malware being added to Poiyomi Shaders," which was never true. Even though files were hosted on VCC Repositories and in our Discord Server, you cannot edit files that were already uploaded. Regardless, we took the Repositories offline just in case.

I, myself (BluWizard) as the sole maintainer of the Poiyomi Documentation, was unaffected. Months ago, Poiyomi granted me management access to Vercel (our hosting provider for the Documentation). When the incident occurred and the PoiyomiDocs repository got taken offline temporarily with Poiyomi's GitHub account, I was able to temporarily change the Git Repo to my fork of PoiyomiDocs so that I could still maintain it. This allowed me and Tony_Lewis to post the same announcement made in the Discord Server on here about the incident and an FAQ. If Poiyomi didn't graciously grant me permissions to maintain our host, the website would have been "frozen" with no way to update information and a lot of unanswered questions. I am forever grateful for Poiyomi's trust in me to maintain the Documentation on his behalf.

Meanwhile on our Discord Server, we were flooded with lots of comments, questions, and complaints during that whole week. It was not easy for us, even for Tony_Lewis.

The Aftermath​

Few hours passed after the attack happened, and eventually it all stopped. The malicious actor attempted to hold their account at ransom, but it reached a point where that was not possible thanks to the sheer amount of security measures we had in place. In the end, all parties involved reached a dead-end. Nobody, not even the attacker, could go any further. This whole game of chess resulted in a stalemate.

The whole situation wasn't over yet, however. Poiyomi was MIA as he was still working tirelessly to fully recover from the cyber attack. Identity theft reports were filed and many emails were sent.

As Poiyomi started to slowly bring his accounts online after fully regaining access, their GitHub Repositories started to come back online. It was time to rejoice! Although, many people argued that they didn't wanna risk being attacked either. Even so, we analyzed all the files once back online and we found NO changes made on GitHub. The files are still 100% safe to use, which was a huge relief.

The most important thing to express here is that this attack was caught on very early. If this went on for much longer without catching it early on, this situation could have been far more worse than we could have imagined.

What Can I Do to Protect Myself?​

The strongest defense these days is yourself. Yes, it's not the greatest answer I can give, but you can have the strongest defense against cyber attacks if you know exactly what to do. Here are some advice I can personally share on how to best protect your account:

  • USE FIDO2-based Security Passkeys that cryptographically bind authentication to specific devices and websites.
    • I personally utilize FIDO2-based YubiKeys on my accounts, which are USB devices that cryptographically authenticates your login during Multi-Factor Authentication.
  • USE Device Bound Session Credentials (DBSC) if available.
    • Google's Device Bound Session Credentials (DBSC), available in Chrome v146 and newer, binds authentication sessions to a specific device using the Trusted Platform Module (TPM) on Windows. This means if the token was stolen, it is useless on other computers because of your TPM module. In fact, this is one reason why TPM 2.0 is a requirement for Windows 11.9
  • HAVE shorter session lifetimes to reduce the value of a stolen token.
    • A session that expires after 15 minutes of inactivity is far less useful to an attacker than one valid for several days.
    • If you want to be extra vigilant, configure your Web Browser to automatically clear your Cookies on a scheduled cadence.
  • AUDIT your active browser sessions on Google, Discord, GitHub, etc., and revoke anything you don't recognize.
  • KEEP your preferred Antivirus Software active and up-to-date.
    • Let's face it, Windows Defender cannot be the last line of defense. While Windows Defender detects some token stealers, Bitdefender and Malwarebytes have broader coverage of detecting them. Regardless, YOU are the last line of defense against any attack!
  • DO NOT install software from unverified sources, even if they seem trusted! Think twice, analyze, and research before installing legitimate software.
    • This obviously includes modpacks, as described in this post. .jar files can be contaminated with malware if you're not careful!
  • IF a friend DMs you (most often randomly) about anything, watch the conversation pattern. If it feels off or unusual from what you are acquainted with, raise a red flag, ask a personal question that your friend would only know about you, and exercise caution.
    • Sometimes when I receive a random DM from a friend with unusual messaging patterns and they insist me to do something, I like to rage-bait them to the point where they would just give up. The results can be hilarious.
  • SETUP a SIM PIN to protect yourself from a "sim swap" attack. A "sim swap" is what happens when an attacker tricks your carrier to change your SIM card registration remotely without requiring them to physically change your SIM card.10
    • Falling victim to a sim swap attack is even more horrific than a login token being stolen because an attacker can use your Phone Number to login to your accounts without your knowledge. Scary!
    • Both iPhone and Android users can set up a SIM PIN in your phone's Carrier Settings. You would need to first enter the default PIN (provided by your carrier). Then, change it to a PIN that you will remember. That's it!

Conclusion​

To be frankly honest, cybersecurity is extremely important in this day and age. With AI booming with popularity and big media prioritizing fear-mongering propaganda, it is vital that you carefully guard your online accounts with a sense of urgency on a daily basis. You never know when everything you care about online goes away in a blink of an eye.

Thank you for reading and please stay safe out there!

Footnotes​

  1. Poiyomi Hacked? VRChat users warned not to download or update shaders ↩

  2. Poiyomi Shaders Compromised in Targeted Minecraft Social Engineering Attack ↩

  3. New Fractureiser malware used CurseForge Minecraft mods to infect Windows, Linux ↩

  4. Infected Minecraft Mods Lead to Multi-Stage, Multi-Platform Infostealer Malware ↩

  5. Minecraft Mods used to Spread Malware ↩

  6. Session Hijacking: How Attackers Bypass Your Defenses ↩

  7. Session Cookie Theft: You Showed Your ID at the Door. But Someone Else Has Your Room Key ↩

  8. Session Hijacking vs Stolen Cookies: Real-World Attack Scenarios & Detection ↩

  9. What Is a Trusted Platform Module (TPM)? ↩

  10. Hijacked by a Text: Understanding and Preventing SIM Swapping Attacks ↩

Upcoming Changes to the Documentation for 10.0

· 6 min read
BluWizard
Lead Docs Author, Community Helper, Shader Contributor

Hi, BluWizard here! As the maintainer of the Poiyomi Shaders Documentation, I would like to share some changes being made to the Documentation in preparation for 10.0.

As some of your Patreon subscribers already know, Poiyomi Pro 10.0 is now available and is ready for open testing. Before 10.0 can be released to the public as Poiyomi Toon (Free), some changes must be made to this website so that the transition is seamless and that information stays relevant and up-to-date.

This also includes a full transition from being able to download Poiyomi Pro into our brand new system used on pro.poiyomi.com , which is far more reliable than Discord for various technical reasons. That being said, all future downloads of Poiyomi Pro will be handled from that sub-domain moving forward.

Now, let's get into the most important changes...

Docs Versioning​

As of recent updates, we have implemented the usage of the Docusaurus Versioning CLI to create versions of each page in the documentation that shows context based on the version selected. It appears as a version dropdown on the Header, which looks like this:

Dropdown Menu to switch between versions.

Figure 1: Version Dropdown

When you hover your mouse over it, you will see some version numbers. By default, the latest version will be what has been set as the default in our configuration. If you select an older version (such as 9.3), the context of the documentation page you are viewing will significantly change.

This means that if you happen to be using an older version, you can now use this dropdown to view accurate information on what you're looking for. Because of how 10.0 has a gigantic amount of changes across the shader overall, this will be how we will control our context for future versions. By default, the "latest" will be shown (which is 10.0). If you happen to be viewing context with an older version selected, a yellow-colored banner will appear as a gentle reminder.

If a new version becomes available, we will run a CLI command that basically "archives" a copy of all pages into a special "versioned_docs" directory. So if and when 10.1 releases in the distant future, we will run a command that makes all current (10.0) documentation be archived as a previous version, thus making any new edits be seen as 10.1 (latest version) and the Version Dropdown gets updated.

As a result, this allows our visitors to always find relevant information for the version of the shader they are using. Now while it could make it difficult for contributors to help improve our documentation, we barely get any changes to older versions. So there is less of a reason to edit or update older pages for older shader versions unless deemed absolutely necessary.

You can view more technical details of how this system works here .

Download & Install Instructions​

As some people may have already noticed, our Download & Install instructions have been overhauled as requested by Poiyomi.

To start, Poiyomi Toon (the public Free version) now recommends ALCOM / Creator Companion as our recommended installation method. This is because we find this method to be far more manageable and easier for the majority of our users, as the package is coded to automatically remove conflicting Poiyomi Shaders versions (if any are detected) before it is installed in the project. It also now contains scripts that hardens the process to ensure edgy avatar creators who like to include a copy of Poiyomi Shaders with their Avatar packages to never have their conflicting copy imported in the first place (essentially removing the _PoiyomiShaders folder from the import dialogue). A Debug message will throw in the console when this happens, so you'll know. If you are reading this and are one of those avatar creators still doing this practice, please stop doing that!

Secondly, for our Poiyomi Pro users, all Poiyomi Pro Unity Packages starting with 10.0 will now be posted on pro.poiyomi.com from now on. We will be deprecating posting our Unity Packages from our Discord server moving forward, as Discord's inability to maintain the platform's security and Patreon's inability to make the Discord Bot reliable makes using Discord for Patreon Authentication a very difficult process for everyone. Thus, authenticating from our new pro.poiyomi.com website has proven to me much more reliable and has faster authentication timing from Patreon in comparison, so we highly recommend you bookmark that website.

Please take a read through our updated Download & Install instructions to see all the options now available to you.

Docusaurus Upgrades​

We are transitioning our framework to prepare for breaking changes that will be introduced in Docusaurus v4.0, which is due out sometime this year. This major upgrade will introduce optimized build infrastructure, including Rspack, SWC, LightningCSS, optimized storage, and stricter guidelines on writing.

MDX guidelines will become more stricter with the syntax without having to rely on proprietary Docusaurus syntax on top of MDX. Since the ecosystem is widely moving to MDX v3, we have transitioned all pages to the .mdx file extension so that this website is future-proofed against it. The upside of this is that this will allow our documentation to be more portable with external tools like Prettier, ESLint, TypeScript, VSCode, and GitHub to better understand the format. This greatly improves compatibility with the Unified ecosystem and the MDX Playground.

Alongside all these changes, Admonitions, Comments, and Heading IDs are getting an upgrade which will be noted in the CONTRIBUTING document for our contributors to read over.

With that being said, if you are reading this and are maintaining your own Docusaurus website (I know VRChat uses it for their Creators Docs), I highly recommend you read the full blog post here on Docusaurus v3.10 release, which details how to prepare your website for Docusaurus v4.0.

Conclusion​

There is a lot more work to be done as Poiyomi 10.0 is continuously being worked on each day to ensure it is fully stable when the big day comes (the full release of the 10.0 Free version, that is). I am continuously editing, updating, and proofreading everything that I learn from each new update. If you find some information that is either inaccurate, conflicting, or find tomfoolery of any kind, please don't hesitate to reach out by opening an Issue on our Docs Repository as this helps me stay organized on what needs to be done.

Introducing Poiyomi 9.2

· 3 min read
BluWizard
Lead Docs Author, Community Helper, Shader Contributor

Heya, BluWizard here! Just wanna hop in to give you some info on Poiyomi 9.2, a major update to the shader that has just released!

While most of the features haven't changed, this update has introduced native support for VRC Light Volumes, an excellent voxel-based Light Probes replacement for VRChat Worlds. Alongside that, are various amount of bug fixes and improvements! See the Changelog Blog for all the details.

VRC Light Volumes​

What's so special about VRC Light Volumes is that it allows for more natural lighting to show on your Avatar, making for stellar appearances in photos. Here are just two examples of what this can look like on Sacred's Avatar...

Light Volume Example 1

Light Volume Example 2

Notice that in these images above, the light tubes are able to emit very evenly across the Body. Compared to before, it was only able to be an approximate.

Here's a comparison on DrBlackRat's Avatar. Pay attention to the differences between Poiyomi 9.2 (latest) vs. Poiyomi 9.1 (older version)...

Light Volumes vs. None Comparison

As you can see, the results can be very obvious! The Material appears more evenly illuminated from the environment compared to previously.

Since VRC Light Volumes was created since earlier this year, you should begin to notice more and more Worlds adopt this system. Adding support for VRC Light Probes can make the shader future-proof to newer Worlds that plan to take advantage of this new lighting system.

The best part of all this? You don't have to do anything to your Materials! It's automatically enabled by default. All you need to do is make sure to update to the latest version of Poiyomi Shaders and just simply set your Materials to use the latest version.

Vertex Options Reorganized​

Let's quickly talk about another significant change introduced in 9.2. Those who have used Vertex Options, Vertex Glitching, and Vertex Colors should read this!

In the latest version, you may have noticed that those sections have gone missing from the Color & Normals category. This is intentional! We have reorganized them into a brand new category in the shader UI, under Vertex Options. It is located in-between AudioLink and Global Modifiers & Data section.

New Location of Vertex Options

Underneath this area, we have renamed those sections into simply, Basics & Fun, Glitching, and Vertex Colors respectfully. If you have used these features under the old names before, don't worry! All your existing configurations should transition over seamlessly when updating your Materials.

Why did we do this? Well, this is to make way for another upcoming vertex-based feature called LookAt, which is right now being tested in the Pro version of the shader. We'll talk about that sometime in the future.

Conclusion​

We hope you enjoy these new improvements to Poiyomi Shaders! As always, feel free to shoot us a message in our Discord Server for any questions or comments. Also if you have any pictures of your Avatars using the newest version, we invite you to share them there in our #showcase and #in-game-pics channels!

Click here to see the Patch Notes

Major Revamps to the Poiyomi Documentation

· 4 min read
BluWizard
Lead Docs Author, Community Helper, Shader Contributor

Greetings! My name is BluWizard. I've been one of the recent active contributors to the Poiyomi Shaders Documentation, bringing everything up-to-date with 9.0 and finishing up some areas that needed attention.

I would like to talk about some of the major updates that I'm bringing to the Documentation. These overhauls will help bring it more in line with our goals with the Poiyomi Shaders Documentation, as well as bring it more in-line with how similar Documentations organize their pages and helpful resources. We hope these updates will encourage more frequent usage of the Documentation, rather than just trying to search Discord for an answer.

Let's start of with the big one... A brand new Home Page!​

Instead of providing just completion status, I made the Home Page look more presentable and professional. Not only it introduces what known features you can do with the Shader, but has two new Buttons that will redirect you where to Download & Install the shader, as well as a link to Join the Discord Server.

I have appended some of the relevant information back to the Introduction page, which will now act as the Docs Hub. It talks about how to navigate the Documentation, as well as our Completion Status. As for links to Download the Shader, it has been moved into an entirely dedicated page.

Speaking of, let's talk about the new Download & Install page!​

This is going to be your new one-stop shop to learn how to Download, Install, and Update Poiyomi Shaders. Since we both maintain a classic Manual Unity Package version and a VCC Version, we now detail instructions on how to use either one. We list both Method 1. and Method 2. as the instructions.

We prefer that the users choose which method they wish to use when downloading and installing the Shader. While Method 1. Manual Unity Package is preferred, a growing number of users may have a better experience using Method 2. Creator Companion to install the Shader due to it's ease-of-use.

Regardless, whichever method you use is up to you, but keep in mind that the latest version of the Shader will always be available first via Discord before it's distributed on both GitHub, BOOTH, and in the VCC Repo. If you are a Poiyomi Pro user, they will exclusively be available via Discord as always. This is also mentioned on the page.

There are even more changes, down to the small details. Let's break down all the notable visual changes:​

  • Overhauled the Home Page.
    • A more professional, presentable Home Page that gets right to the point and contains relevant information.
    • Added a new Logo.
    • Added Buttons that redirect to Download & Install and as the Discord Server.
  • Added Download & Install Page.
    • Two Methods with Instructions on how to install Poiyomi Shaders, either as a Unity Package or through the Creator Companion.
    • Download Links.
    • Info on the Pro Shader.
  • Improved SEO on various pages.
    • I have given many pages more descriptions and keywords for SEO (Search Engine Optimization), so that the Documentation and the website as a whole can appear clearly on Search Engines.
  • Fixed a lot of Image and Video Sizing to be more consistent.
    • For a while, this Documentation was not very mobile-friendly. I've implemented some changes to React JS that makes the embedded videos have more responsive width, regardless of display size. This eliminates an issue where the embedded videos would extend far beyond the width constrains on a Mobile Web Browser. By default, all Images and Videos will now be automatically responsive based on your browser's width, with some exceptions on certain Documentation entries.
  • Upgraded Docusaurus to v3.3.2.
    • Docusaurus v3.3.2 introduces major improvements, bug fixes, and new features for us to use in the near future.
    • React, MDX, and Node.js have been updated as a result of the Docusaurus v3 Upgrade.
    • The Light and Dark Theme will now automatically match the user's client by default.
  • Removed irrelevant information and old pages in favor of the new Download & Install page.
    • The Poiyomi VCC Repo Page is no longer necessary, as I've implemented a button in the Download & Install page for the VCC Version that directly opens the Creator Companion App, adding the Repository.
    • Redirects added to the website configuration to handle old links.

Conclusion​

We are continuously working on improving the Documentation with as much information as possible in an easy-to-understand fashion. If you have any feedback, feel free to drop us a line in the Discord Server. Other than that, we hope you enjoy these new updates!