Threat actors have been abusing Steam Workshop since at least late 2025 to distribute malware hidden inside Wallpaper Engine application wallpapers. Because Wallpaper Engine supports executable Windows applications as wallpapers, attackers uploaded malicious packages that auto-execute upon installation. Kaspersky researchers found dozens of such wallpapers, each downloaded thousands of times, delivering payloads including the DarkKomet backdoor, Lumma and Vidar infostealers, cryptocurrency miners, botnet loaders, and ransomware. Steam has removed the identified malicious wallpapers, but researchers warn new ones are likely to appear. Users are advised to scan Workshop downloads with up-to-date antivirus software.
91 Impressions