Kaspersky discovers malware campaign on Steam's Wallpaper Engine targeting user accounts
By
Nathan Warby
Toasted just enough. A reliable bake, gently seasoned.
Summary
Cybersecurity firm Kaspersky has discovered a malware campaign on Steam's popular Wallpaper Engine app, where hackers hid malicious software inside custom wallpaper downloads. Dozens of infected wallpapers were found, some with tens of thousands of downloads, designed to steal user accounts and other sensitive data. Steam users are urged to exercise caution when downloading custom wallpapers.
Key quotes
· 3 pulledSteam users are being urged to be careful when downloading custom wallpapers after a malware campaign was discovered in Wallpaper Engine.
Attackers have been hiding malicious software inside wallpaper downloads shared through Wallpaper Engine, one of Steam's most popular customization apps.
Dozens of infected wallpapers were discovered, with some racking up thousands or even tens of thousands of downloads before being identified.
You might also wanna read
Malware spreading through Steam Workshop wallpapers targets gamers in China and Russia
Since late 2025, malware has been spreading through Steam Workshop via Wallpaper Engine's live wallpaper sharing feature. Attackers are targ
Valve removes free horror game "Beyond The Dark" from Steam after malware discovery
Valve removed the free horror game "Beyond The Dark" from Steam after players discovered it contained malware designed to steal personal dat
JDownloader website hacked, served malware to Windows and Linux users for over a day
The JDownloader website was compromised by attackers who replaced legitimate download files with malware for over a day, targeting Windows a
Valve Anti-Cheat (VAC): Overview and Implementation in Games
Valve Anti-Cheat (VAC) was created by Valve in 2002 and operates in User Mode without a kernel component. It was first implemented in Counte
Major NPM Supply Chain Attack: @ctrl/tinycolor and 40+ Packages Compromised with Self-Propagating Malware
A sophisticated supply chain attack has compromised the popular @ctrl/tinycolor NPM package (with over 2 million weekly downloads) along wit
ShadyPanda's 7-Year Malware Campaign Infected 4.3 Million Browsers Through Malicious Extensions
Koi researchers have uncovered a seven-year malware campaign by threat actor ShadyPanda that infected 4.3 million Chrome and Edge browsers t
