Malware hidden in Steam Wallpaper Engine packages steals accounts
Kaspersky found malware inside Wallpaper Engine packages on the Steam Workshop that ran code when installed and were used to steal Steam accounts, mainly in China and Russia.
Kaspersky researchers found that attackers hid malware inside interactive and animated wallpaper packages distributed on the Steam Workshop for the Wallpaper Engine app. The malicious packages ran code on Windows PCs when users installed the wallpapers and were used to capture Steam account credentials. The campaign primarily targeted users in China and Russia, with additional victims identified in Singapore, Hong Kong, Germany and Canada.
The infected wallpapers are often Windows executables. Attackers bundled payloads into those executables so the malware would launch during installation. In several cases the malicious files were placed inside password-protected archives included in the wallpaper package; those archives then executed automatically when the package installed.
Kaspersky tracked dozens of compromised packages on the Workshop and estimated that some had been downloaded tens of thousands of times, increasing the number of potentially affected accounts. Researchers observed that most infections aimed to harvest Steam login data, and in some incidents the attackers deployed other information-stealing programs.
The compromised content came from the Steam Workshop, a community area where users upload and share custom wallpapers. Wallpaper Engine and Steam do not produce those community packages; the report said threat actors were exploiting the platform’s user-generated content to deliver malware. Kaspersky noted the findings do not point to a flaw in Wallpaper Engine or Steam’s core applications, but they illustrate risks when installing third-party content that can execute code.
Kaspersky advised users to verify creators, read comments and ratings, avoid installing packages that include executable files or encrypted archives unless the origin is certain, and keep antivirus software up to date. The report included a direct warning: “Trusted platforms can be abused to distribute malware.”
The incident follows other recent campaigns that used game-related software and mods to spread malicious code. Earlier this year, fake game clients and modified files infected more than 100,000 users, delivering software capable of managing or deleting files, hijacking webcams and providing remote access to compromised machines.







