"Bluehole BUGP CORP have left the byte-stream unencrypted so packets can be read in "plain text" and anyone with that knowledge can make toys for this game without triggering battle eye.
The byte-stream is sent in plain-text by default because blue-hole PUGBUG#1 thought it wasn't a big enough deal to change the default serialization even slightly for the game. In contrast, ARK has an encrypted byte-stream, 10k networked entities at most times and has 'no problems' with it, There is literally no excuse for this kind of exploit in a game like PUBG with a magnitude less networked entities.
What I'm saying is that bluehole CORPG PUB allows every player to see and makes no effort to hide;
Every Player Name
Every Player Location (every axis, so you can tell if someone is up-stairs for example)
What direction every player is looking
What Items are nearby
With just this information from the game packets you can make every toy without even touching the game.
This is how most of "china no.1" toys are working and not being detected by battle-eye.
How could things possibly get worse... right??
.....The most commonly known china no.1 toy is also using a seemingly undetected unedited! signed version of a detected method (detours-64bit, signed by NetEase(Hangzhou) Network Co. Ltd.) so thats a hilarious coincidence too because you'd think BE would already have a sig for that or would simply sig the certs signature but apparently they've been using the same one since "Wednesday, October 18, 2017 3:08:01 PM"
PUBG Corp have been in contact and forwarded this info (+ other info) to the relevant teams, Yay

"