Threats · 90 days ago
Steam Workshop content for Wallpaper Engine can behave like a desktop program, so a wallpaper can become code execution, not just a cosmetic download. That means one install can steal a Steam account and leave the Windows host behind with a backdoor or miner; cleaning up the account alone can miss the machine.
Kaspersky says malicious Wallpaper Engine packages have been spreading through Steam Workshop since late 2025. The packages have carried old commodity infostealers such as DarkKomet, Lumma, and Vidar, and the researcher found dozens of malicious application wallpapers that had been downloaded thousands of times.
The risk is in the trust model: community content is being used as a delivery path for executable malware. If users install add-ons or themes that can run code, the store itself becomes an execution path, not just a content library.
2 sources covering this story
Steam Workshop abused to spread malware via Wallpaper Engine app
Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages.
Gamers beware: malicious wallpapers on Steam found stealing accounts
Since late 2025, malware has been spreading rapidly through the Steam Workshop.
Part of the PlainSec briefing for 2026-06-17