Steam Workshop content for Wallpaper Engine can behave like a desktop program, so a wallpaper can become code execution, not just a cosmetic download. That means one install can steal a Steam account and leave the Windows host behind with a backdoor or miner; cleaning up the account alone can miss the machine.
Kaspersky says malicious Wallpaper Engine packages have been spreading through Steam Workshop since late 2025. The packages have carried old commodity infostealers such as DarkKomet, Lumma, and Vidar, and the researcher found dozens of malicious application wallpapers that had been downloaded thousands of times.
The risk is in the trust model: community content is being used as a delivery path for executable malware. If users install add-ons or themes that can run code, the store itself becomes an execution path, not just a content library.