Overview
- Kaspersky published a report Friday saying it found dozens of Wallpaper Engine packages in the Steam Workshop that hide executable files, scripts or password‑protected archives which run on Windows machines.
- Researchers showed the malicious packages can run external code during installation by bundling executables or auto‑extracting archives whose passwords are sometimes published with the upload.
- The attackers primarily use info‑stealers and backdoors to harvest Steam credentials and then load further payloads such as ransomware, cryptominers or remote loaders.
- The campaign appears to be run by multiple groups and often uses adult‑themed anime as bait to increase downloads and discourage victims from reporting infections, with cases focused on China and Russia and some reports in Germany.
- Valve removed the flagged wallpapers and suspended the implicated accounts after Kaspersky's disclosure and users are advised to avoid app‑style wallpapers from the Workshop, verify sources and run up‑to‑date antivirus tools to detect and quarantine suspicious files.