Thumbs upWindows Node.js CSGO Radar + Triggerbot

Posts 115 of 16 · Page 1 of 2
Windows Node.js CSGO Radar + Triggerbot
Hello welcome to my first post, so one day I was just making a simple nodejs windows user32.dll program to automate some stuff I do at work, and then I found out CSGO went free to play and figured why not have a crack at it. I basically hacked together trigger bot and a radar hack in node. I'v been using it for the past 4 days and it seems to be undetected by any anti cheat systems.

I'm using node version 10.13.0
npm version 6.4.1

modules you will need to install: ( npm i memoryjs util ffi colors )

'memoryjs' to read and write memory to csgo
'util' for some debugging stuff
'ffi' to do some clicking and stuff with user32.dll
'colors' for some snazzy console output

This code is extremely bad, I don't write like this normally, I did a lot of copy and pasting from c++ programs and re writing them in js, so be warned, this is a heep of garbage, but I feel like I need to share it because it was only possible because of the talented coders sharing their works here. I'm working on wrapping it up into an exe and extend it's features, so if you stay tuned I might be able to get that going for yall who can't get node configured.

If you have node installed and configured properly...

1) make a folder call it what ever you want
2) open up code editor or notepad, paste code into it, save it as whatever you want but it has to end in '.js'
ex: 'icantaim.js', 'everyonehacksanyway.js', 'welcometohell.js'
3) npm init the folder you just made
4) npm i memoryjs util ffi colors
5) start csgo (WAIT UNTIL GAME IS FULLY LOADED UNTIL YOU GO TO STEP 6 BRUH)
6) now just `node 'yourfilenamehere.js'` and if you get the magenta line of text that explains the hotkeys, you should be golden.

If you have anyone questions let me know, this isn't supposed to be much of a guide, just releasing back source that I came up with by browsing this board.

Code:
var mem = require('memoryjs')
const ffi = require('ffi')
const util = require('util')
const colors = require('colors')
const user32 = ffi.Library('user32.dll', {
    mouse_event: ['void', ['int', 'int', 'int', 'int', 'int']],
    GetKeyState: ['short', ['int']]
})
// hazedumper offsets
let offsets = {
    "clientstate_choked_commands": 19632,
    "clientstate_delta_ticks": 372,
    "clientstate_last_outgoing_command": 19628,
    "clientstate_net_channel": 156,
    "convar_name_hash_table": 192760,
    "dwClientState": 5811452,
    "dwClientState_GetLocalPlayer": 384,
    "dwClientState_IsHLTV": 19656,
    "dwClientState_Map": 652,
    "dwClientState_MapDirectory": 392,
    "dwClientState_MaxPlayer": 784,
    "dwClientState_PlayerInfo": 21056,
    "dwClientState_State": 264,
    "dwClientState_ViewAngles": 19728,
    "dwEntityList": 80534716,
    "dwForceAttack": 51377016,
    "dwForceAttack2": 51377028,
    "dwForceBackward": 51377100,
    "dwForceForward": 51377112,
    "dwForceJump": 85397104,
    "dwForceLeft": 51377136,
    "dwForceRight": 51377124,
    "dwGameDir": 6491760,
    "dwGameRulesProxy": 85864868,
    "dwGetAllClasses": 13506988,
    "dwGlobalVars": 5810688,
    "dwGlowObjectManager": 86039264,
    "dwInput": 85035600,
    "dwInterfaceLinkList": 9038228,
    "dwLocalPlayer": 13358756,
    "dwMouseEnable": 13382128,
    "dwMouseEnablePtr": 13382080,
    "dwPlayerResource": 51369756,
    "dwRadarBase": 84945404,
    "dwSensitivity": 13381772,
    "dwSensitivityPtr": 13381728,
    "dwSetClanTag": 562640,
    "dwViewMatrix": 80475860,
    "dwWeaponTable": 85038356,
    "dwWeaponTableIndex": 12860,
    "dwYawPtr": 13381200,
    "dwZoomSensitivityRatioPtr": 13402256,
    "dwbSendPackets": 860618,
    "dwppDirect3DDevice9": 671680,
    "interface_engine_cvar": 256492,
    "m_bDormant": 237,
    "m_pStudioHdr": 10572,
    "m_pitchClassPtr": 84946096,
    "m_yawClassPtr": 13381200,
    "model_ambient_min": 5823772,
    "cs_gamerules_data": 0,
    "m_ArmorValue": 45864,
    "m_Collision": 796,
    "m_CollisionGroup": 1140,
    "m_Local": 12220,
    "m_MoveType": 604,
    "m_OriginalOwnerXuidHigh": 12724,
    "m_OriginalOwnerXuidLow": 12720,
    "m_SurvivalGameRuleDecisionTypes": 4888,
    "m_SurvivalRules": 3312,
    "m_aimPunchAngle": 12332,
    "m_aimPunchAngleVel": 12344,
    "m_bBombPlanted": 2461,
    "m_bFreezePeriod": 32,
    "m_bGunGameImmunity": 14632,
    "m_bHasDefuser": 45880,
    "m_bHasHelmet": 45852,
    "m_bInReload": 12933,
    "m_bIsDefusing": 14612,
    "m_bIsQueuedMatchmaking": 116,
    "m_bIsScoped": 14602,
    "m_bIsValveDS": 117,
    "m_bSpotted": 2365,
    "m_bSpottedByMask": 2432,
    "m_clrRender": 112,
    "m_dwBoneMatrix": 9896,
    "m_fAccuracyPenalty": 13060,
    "m_fFlags": 260,
    "m_flC4Blow": 10640,
    "m_flDefuseCountDown": 10668,
    "m_flDefuseLength": 10664,
    "m_flFallbackWear": 12736,
    "m_flFlashDuration": 41952,
    "m_flFlashMaxAlpha": 41948,
    "m_flNextPrimaryAttack": 12824,
    "m_flTimerLength": 10644,
    "m_hActiveWeapon": 12024,
    "m_hMyWeapons": 11768,
    "m_hObserverTarget": 13192,
    "m_hOwner": 10700,
    "m_hOwnerEntity": 332,
    "m_iAccountID": 12232,
    "m_iClip1": 12868,
    "m_iCompetitiveRanking": 6788,
    "m_iCompetitiveWins": 7048,
    "m_iCrosshairId": 45972,
    "m_iEntityQuality": 12204,
    "m_iFOV": 12772,
    "m_iFOVStart": 12776,
    "m_iGlowIndex": 41976,
    "m_iHealth": 256,
    "m_iItemDefinitionIndex": 12202,
    "m_iItemIDHigh": 12224,
    "m_iObserverMode": 13172,
    "m_iShotsFired": 41840,
    "m_iState": 12856,
    "m_iTeamNum": 244,
    "m_lifeState": 607,
    "m_nFallbackPaintKit": 12728,
    "m_nFallbackSeed": 12732,
    "m_nFallbackStatTrak": 12740,
    "m_nForceBone": 9868,
    "m_nTickBase": 13356,
    "m_rgflCoordinateFrame": 1092,
    "m_szCustomName": 12348,
    "m_szLastPlaceName": 13744,
    "m_thirdPersonViewAngles": 12760,
    "m_vecOrigin": 312,
    "m_vecVelocity": 276,
    "m_vecViewOffset": 264,
    "m_viewPunchAngle": 12320
}
console.log(`Press the ALT key to scan\ncrosshairId for enemy players\n\nPress 'O' to toggle radar.`.magentaBG)
// these variables are here just so the interval dosn't spam the console.log with useless shit
var scanOnLogBouncer = false
var scanOffLogBouncer = false
var radarOnLogBouncer = false
var radarOffLogBouncer = false
setInterval(() => {
    var procName = "csgo.exe"
    var proc = mem.openProcess(procName)
    var clientModule = mem.findModule("client_panorama.dll", proc.th32ProcessID)
    var engineModule = mem.findModule("engine.dll", proc.th32ProcessID)
    var cDLL = clientModule.modBaseAddr
    var eDLL = engineModule.modBaseAddr
    var localPlayer = mem.readMemory(proc.handle, cDLL + offsets.dwLocalPlayer, "dword")
    var localPlayerTeam = mem.readMemory(proc.handle, localPlayer + offsets.m_iTeamNum, "int")
    var localInCross = mem.readMemory(proc.handle, localPlayer + offsets.m_iCrosshairId, "int")
    var inCrossEntity = mem.readMemory(proc.handle, cDLL + offsets.dwEntityList + ((localInCross - 1) * 0x10), "dword");
    var inCrossEntityTeam = mem.readMemory(proc.handle, inCrossEntity + offsets.m_iTeamNum, "int")
    if ((user32.GetKeyState(0x12) !== 0) && (user32.GetKeyState(0x12) !== 1)) {
        if (scanOnLogBouncer === false) {
            scanOnLogBouncer = true
            scanOffLogBouncer = false
            console.log(`scanning crosshairId`.yellowBG)
        }
        if (localPlayerTeam === inCrossEntityTeam) {
            console.log(`looking at friendly`.greenBG)
        }
    } else {
        if(scanOffLogBouncer === false){
            scanOffLogBouncer = true
            scanOnLogBouncer = false
            console.log(`not scanning crosshairId`.yellowBG.red)
        }
    }
    if (((localInCross > 0) && ((user32.GetKeyState(0x12) !== 0) && (user32.GetKeyState(0x12) !== 1))) && (localPlayerTeam !== inCrossEntityTeam)) {
        console.log(`shooting at enemy`.redBG)
        user32.mouse_event(2, 0, 0, 0, 0) // mouseLeft down
        user32.mouse_event(4, 0, 0, 0, 0) // mouseLeft up
    }
    if (user32.GetKeyState(0x4F) === 1) {
        if (radarOnLogBouncer === false) {
            console.log('radar on'.green)
            radarOnLogBouncer = true
            radarOffLogBouncer = false
        }
        for (var i = 0; i < 300; i++) {
            var entityToCheck = mem.readMemory(proc.handle, cDLL + offsets.dwEntityList + ((i + 1) * 0x10), "dword")
            var entityToCheckTeam = mem.readMemory(proc.handle, entityToCheck + offsets.m_iTeamNum, "int")
            var entityToCheckDormant = mem.readMemory(proc.handle, entityToCheck + offsets.m_bDormant, "int")
            if (localPlayerTeam !== entityToCheckTeam && (entityToCheckTeam === 2 || entityToCheckTeam === 3) && entityToCheckDormant === 0) {
                mem.writeMemory(proc.handle, entityToCheck + offsets.m_bSpotted, 1, 'int')
            }
        }
    } else if (user32.GetKeyState(0x4F) === 0) {
        if(radarOffLogBouncer === false){
            console.log('radar off'.red)
            radarOffLogBouncer = true
            radarOnLogBouncer = false
        }
    }
    setTimeout(() => {
        mem.closeProcess(proc.th32ProcessID)
    }, 1000)
}, 10)
If someone wants to hit me in the dms or just post it as a reply here a guide to making nicer threads (because I'm going to be making update threads as long as people engage and want it) please do because I can't find the docs on this editor thingy for this forum...
@givemeoffsets Why are you looping through the entity list 300 times?
Quote Originally Posted by Sandwich View Post
@givemeoffsets Why are you looping through the entity list 300 times?
Actually no good reason, I read something somewhere saying that play entities can be listed beyond 200 sometimes, just to check really, kinda being safe.

- - - Updated - - -

Quote Originally Posted by brucemalis View Post
Interesting, going to play with this some. Thanks for the share
No problem man, I made it with lots of help from this forum, so I had to give it back. Open source for lyfe.
Quote Originally Posted by givemeoffsets View Post
Actually no good reason, I read something somewhere saying that play entities can be listed beyond 200 sometimes, just to check really, kinda being safe.
Unless you are joining a custom server, max players is 32.
Quote Originally Posted by Sandwich View Post
Unless you are joining a custom server, max players is 32.
Are there only players in the entity list? Idk it's structure, I know each entity is 0x10 away from each other in memory, but idk what is in the list, from what iv seen, it's just players?
Quote Originally Posted by givemeoffsets View Post
Are there only players in the entity list? Idk it's structure, I know each entity is 0x10 away from each other in memory, but idk what is in the list, from what iv seen, it's just players?
Yes, it stores the player entities.
Code:
//Basic entity structure, you can add on to it.
struct Entity {
    DWORD dwEntity;
    int iTeam,
        iHealth;
    bool bDormant;
} Entity[32];


void Read(int i) {
    Entity[i].dwEntity = mem.Read<DWORD>(mod.Client + offsets.dwEntityList + (i * 0x10));
    if (Entity[i].dwEntity == NULL)
	return;
    Entity[i].iTeam = mem.Read<int>(Entity[i].dwEntity + offsets.m_iTeamNum);
    Entity[i].iHealth = mem.Read<int>(Entity[i].dwEntity + offsets.m_iHealth);
    Entity[i].bDormant = mem.Read<bool>(Entity[i].dwEntity + offsets.dwDormant);
}

for (int i = 0; i < 32; i++) {
    Read(i);
}
Quote Originally Posted by Sandwich View Post
Yes, it stores the player entities.
Code:
//Basic entity structure, you can add on to it.
struct Entity {
    DWORD dwEntity;
    int iTeam,
        iHealth;
    bool bDormant;
} Entity[32];


void Read(int i) {
    Entity[i].dwEntity = mem.Read<DWORD>(mod.Client + offsets.dwEntityList + (i * 0x10));
    if (Entity[i].dwEntity == NULL)
	return;
    Entity[i].iTeam = mem.Read<int>(Entity[i].dwEntity + offsets.m_iTeamNum);
    Entity[i].iHealth = mem.Read<int>(Entity[i].dwEntity + offsets.m_iHealth);
    Entity[i].bDormant = mem.Read<bool>(Entity[i].dwEntity + offsets.dwDormant);
}

for (int i = 0; i < 32; i++) {
    Read(i);
}

Thanks man, I appreciate the clarification.

Do you know if its possible to get he players location like "Middle doors" or "Lower tunnels" by reading memory? I'v been looking all over for that info.
Interesting, going to play with this some. Thanks for the share
Quote Originally Posted by givemeoffsets View Post
Thanks man, I appreciate the clarification.

Do you know if its possible to get he players location like "Middle doors" or "Lower tunnels" by reading memory? I'v been looking all over for that info.
Np. I don't think its possible to read the entity position based off radar locations.
Quote Originally Posted by Sandwich View Post
Np. I don't think its possible to read the entity position based off radar locations.
Well you can get the x,y and z right? I'v never tried to get position before, if you can do that, I think I will begin making some function that will be able to map x,y,z to the radar location names.

Again thanks a lot for the replies bro.
Quote Originally Posted by givemeoffsets View Post
Well you can get the x,y and z right? I'v never tried to get position before, if you can do that, I think I will begin making some function that will be able to map x,y,z to the radar location names.

Again thanks a lot for the replies bro.
Code:
Entity[i].headPos.x = mem.ReadMemory<float>(Entity[i].boneMatrix + (0x30 * 8) + 0xC);
Entity[i].headPos.y = mem.ReadMemory<float>(Entity[i].boneMatrix + (0x30 * 8) + 0x1C);
Entity[i].headPos.z = mem.ReadMemory<float>(Entity[i].boneMatrix + (0x30 * 8) + 0x2C);
Quote Originally Posted by Sandwich View Post
Code:
Entity[i].headPos.x = mem.ReadMemory<float>(Entity[i].boneMatrix + (0x30 * 8) + 0xC);
Entity[i].headPos.y = mem.ReadMemory<float>(Entity[i].boneMatrix + (0x30 * 8) + 0x1C);
Entity[i].headPos.z = mem.ReadMemory<float>(Entity[i].boneMatrix + (0x30 * 8) + 0x2C);
yaassss thank you so much bro exactly I was looking for, gonna be busy all night now. Also I figured out the exe packaging thing, so I'll be able to make a simple exe to run to get the hack going, gonna take a few days to clean the code and get everything working right.
Quote Originally Posted by givemeoffsets View Post
yaassss thank you so much bro exactly I was looking for, gonna be busy all night now. Also I figured out the exe packaging thing, so I'll be able to make a simple exe to run to get the hack going, gonna take a few days to clean the code and get everything working right.
Cool, have fun.
Got a working aim bot with glows now

Code:
const localPlayerXYZOffset = mem.readMemory(proc.handle, localPlayer + offsets.m_vecViewOffset, 'vec3')
let localPlayerXYZ = mem.readMemory(proc.handle, localPlayer + offsets.m_vecOrigin, 'vec3')
localPlayerXYZ.x = localPlayerXYZ.x + localPlayerXYZOffset.x
localPlayerXYZ.y = localPlayerXYZ.y + localPlayerXYZOffset.y
localPlayerXYZ.z = localPlayerXYZ.z + localPlayerXYZOffset.z
const localPlayerViewAngles = mem.readMemory(proc.handle, clientState + offsets.dwClientState_ViewAngles, "vec3")
const playerDormant = mem.readMemory(proc.handle, inCrossEntity + offsets.m_bDormant, "int")
const enemyPlayerTeam = mem.readMemory(proc.handle, inCrossEntity + offsets.m_iTeamNum, 'int')
const enemyPlayerHealth = mem.readMemory(proc.handle, inCrossEntity + offsets.m_iHealth, 'int')
if (playerDormant === 0 && localPlayerTeam !== enemyPlayerTeam && enemyPlayerHealth > 0) {
    mem.writeMemory(proc.handle, inCrossEntity + offsets.m_bSpotted, 1, 'int')
    const enemyPlayerBoneMatrix = mem.readMemory(proc.handle, inCrossEntity + offsets.m_dwBoneMatrix, 'dword')
    const enemyPlayerHeadX = mem.readMemory(proc.handle, enemyPlayerBoneMatrix + 0x30 * 6 + 0x0C, 'float')
    const enemyPlayerHeadY = mem.readMemory(proc.handle, enemyPlayerBoneMatrix + 0x30 * 6 + 0x1C, 'float')
    const enemyPlayerHeadZ = mem.readMemory(proc.handle, enemyPlayerBoneMatrix + 0x30 * 6 + 0x2C, 'float')
    const R = Math.sqrt(Math.pow(localPlayerXYZ.x - enemyPlayerHeadX, 2) + Math.pow(localPlayerXYZ.y - enemyPlayerHeadY, 2))
    let yTheta = Math.atan((localPlayerXYZ.y - enemyPlayerHeadY) / (localPlayerXYZ.x - enemyPlayerHeadX)) * (180 / Math.PI)
    let xTheta = Math.atan((localPlayerXYZ.z - enemyPlayerHeadZ) / R) * (180 / Math.PI)
    if (localPlayerXYZ.x > enemyPlayerHeadX && localPlayerXYZ.y < enemyPlayerHeadY) {
        yTheta = yTheta + 180
    } else if (localPlayerXYZ.x > enemyPlayerHeadX && localPlayerXYZ.y > enemyPlayerHeadY) {
        yTheta = yTheta - 180
    }
}
Quote Originally Posted by givemeoffsets View Post
Got a working aim bot with glows now

Code:
const localPlayerXYZOffset = mem.readMemory(proc.handle, localPlayer + offsets.m_vecViewOffset, 'vec3')
let localPlayerXYZ = mem.readMemory(proc.handle, localPlayer + offsets.m_vecOrigin, 'vec3')
localPlayerXYZ.x = localPlayerXYZ.x + localPlayerXYZOffset.x
localPlayerXYZ.y = localPlayerXYZ.y + localPlayerXYZOffset.y
localPlayerXYZ.z = localPlayerXYZ.z + localPlayerXYZOffset.z
const localPlayerViewAngles = mem.readMemory(proc.handle, clientState + offsets.dwClientState_ViewAngles, "vec3")
const playerDormant = mem.readMemory(proc.handle, inCrossEntity + offsets.m_bDormant, "int")
const enemyPlayerTeam = mem.readMemory(proc.handle, inCrossEntity + offsets.m_iTeamNum, 'int')
const enemyPlayerHealth = mem.readMemory(proc.handle, inCrossEntity + offsets.m_iHealth, 'int')
if (playerDormant === 0 && localPlayerTeam !== enemyPlayerTeam && enemyPlayerHealth > 0) {
    mem.writeMemory(proc.handle, inCrossEntity + offsets.m_bSpotted, 1, 'int')
    const enemyPlayerBoneMatrix = mem.readMemory(proc.handle, inCrossEntity + offsets.m_dwBoneMatrix, 'dword')
    const enemyPlayerHeadX = mem.readMemory(proc.handle, enemyPlayerBoneMatrix + 0x30 * 6 + 0x0C, 'float')
    const enemyPlayerHeadY = mem.readMemory(proc.handle, enemyPlayerBoneMatrix + 0x30 * 6 + 0x1C, 'float')
    const enemyPlayerHeadZ = mem.readMemory(proc.handle, enemyPlayerBoneMatrix + 0x30 * 6 + 0x2C, 'float')
    const R = Math.sqrt(Math.pow(localPlayerXYZ.x - enemyPlayerHeadX, 2) + Math.pow(localPlayerXYZ.y - enemyPlayerHeadY, 2))
    let yTheta = Math.atan((localPlayerXYZ.y - enemyPlayerHeadY) / (localPlayerXYZ.x - enemyPlayerHeadX)) * (180 / Math.PI)
    let xTheta = Math.atan((localPlayerXYZ.z - enemyPlayerHeadZ) / R) * (180 / Math.PI)
    if (localPlayerXYZ.x > enemyPlayerHeadX && localPlayerXYZ.y < enemyPlayerHeadY) {
        yTheta = yTheta + 180
    } else if (localPlayerXYZ.x > enemyPlayerHeadX && localPlayerXYZ.y > enemyPlayerHeadY) {
        yTheta = yTheta - 180
    }
}
Nice job, you are improving. Add clamp angles, it will prevent you from getting untrusted. Also (b)Spotted is a boolean not an integer.
Code:
void clamp(vector angle)
{
	if (angle.x > 89.0f)
		angle.x += 89.0f;

	else if (angle.x < -89.0f)
		angle.x -= 89.0f;

	if (angle.y > 180.0f)
		angle.y += 180.0f;

	else if (angle.y < -180.0f)
		angle.y -= 180.0f;

	angle.z = 0;
}
Posts 115 of 16 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?