Gamers beware: malicious wallpapers on Steam found stealing accounts
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Since late 2025, attackers have been distributing malware through Steam Workshop by embedding malicious code inside Wallpaper Engine's 'application wallpaper' packages. These wallpapers can silently install backdoors (DarkKomet), infostealers (Lumma, Vidar), crypto miners, and ransomware. One analyzed sample drops a backdoor and a modified system DLL that hunts for Steam credentials and exfiltrates them to attacker-controlled servers. Dozens of infected wallpapers were each downloaded thousands of times, with 89% of victims in China. Steam has removed the identified wallpapers, but new ones keep appearing. Indicators of compromise including MD5 hashes and C2 server addresses are provided.