Crypt0's NewsCrypt0's News

Gaming

Steam Workshop Malware Hits People Playground a Second Time and the Solo Developer Cuts Mods Loose

Steam Workshop failed the same game twice in one year, and this time the developer stopped negotiating. On September 21, 2026, the ragdoll physics sandbox People Playground was hit by a destructive malware payload distributed through a Steam Workshop mod, the second such attack against the title after a nearly identical incident in February. The exposure window ran roughly 6pm to 8pm CEST and covered anyone who launched the game with mods installed during those two hours. The next day, Studio Minus developer mestiez disabled the Workshop entirely and published a Steam announcement titled Bad Event with a blunt assessment, this one is especially bad.

The payload behaved less like a quiet info stealer and more like a worm crossed with a wiper. Based on the developer's warnings and contemporaneous reporting, the malicious mod could delete a substantial volume of a victim's personal files, modify Steam configuration data and Steam Cloud saves tied to other unrelated games, read Discord usernames and identifying details from the local client, and publish stolen information back to the Steam Workshop, turning victims into unwitting distribution points. By grafting malicious code onto already popular mods instead of uploading a fresh suspicious item, the attack rode the existing trust and download momentum of content players had socially vetted through comments, ratings and subscriber counts. That is a fundamentally different threat model from a trojan game, because the delivery mechanism was legitimate community trust itself.

The most alarming part of the timeline is a walk back. The developer first assured players that passwords, session tokens and cookies were untouched. That assurance was later struck from the announcement, and mestiez advised players to change passwords on every important account in case session tokens had been exposed, a caveat that suggests even the developer was still mapping the full scope days later. A Reddit user who dissected the mod claimed it went further still, allegedly hijacking Steam accounts to republish itself and sending slurs to victims' Steam friends. Independent security firms have yet to attach a named malware family to the payload, and a verified count of infected accounts has yet to surface.

Valve's response stayed narrow. Reports indicate the company removed Workshop items containing C# code, deleted items found to contain sensitive user data, and stripped content uploaded or updated on or after September 21. Valve has stayed publicly quiet on any platform wide policy change, issued nothing resembling the advisories the industry uses for serious incidents, and left exposure beyond People Playground's own audience unconfirmed. By September 23 and 24, Studio Minus had shipped a new build that stops mods from running at all, a step beyond disabling uploads, and said full mod support might only return if mods can be made safe by design, a bar that stretches beyond what a one person studio can realistically meet.

This reads as a pattern, and the timeline backs it up. Kaspersky's Securelist research notes that since late 2025, malware has been spreading rapidly through the Steam Workshop, the platform's built in service for sharing custom content. The timeline now includes PirateFi in February 2025, Sniper Phantom's Resolution, Chemia, a Wallpaper Engine campaign that pushed infected animated wallpapers, an FBI victim notice naming seven infected titles, and now a repeat outbreak inside the same game's Workshop. The Workshop was built in 2011 for a smaller and more benign modding community, and its trust model, lightly reviewed user content flowing into a client players trust with their payment details, has fallen behind the financial incentives now attached to compromising gaming accounts.

For players, the practical guidance from the developer stands. If you launched a modded copy of People Playground on September 21, delete everything in the mods folder, run a full antivirus scan, and change the passwords on your important accounts. For the industry, the harder question is structural. Community content platforms across gaming run on the same basic trust assumption, and every new incident feeds the case for independent security review instead of after the fact takedowns. Modding built PC gaming's longevity. Keeping it alive now means rebuilding the trust layer it was founded on, before the next poisoned mod finds it.

Quick answers

What is this story about?

Steam Workshop failed the same game twice in one year, and this time the developer stopped negotiating. On September 21, 2026, the ragdoll physics sandbox People Playground was hit by a destructive malware payload distributed through a Steam Workshop mod, the second such attack against the title after a nearly identical incident in February. The exposure window ran roughly 6pm to 8pm CEST and covered anyone who launched the game with mods installed during those two hours. The next day, Studio Minus developer mestiez disabled the Workshop entirely and published a Steam announcement titled Bad Event with a blunt assessment, this one is especially bad.

Why does this story matter?

For players, the practical guidance from the developer stands. If you launched a modded copy of People Playground on September 21, delete everything in the mods folder, run a full antivirus scan, and change the passwords on your important accounts. For the industry, the harder question is structural. Community content platforms across gaming run on the same basic trust assumption, and every new incident feeds the case for independent security review instead of after the fact takedowns. Modding built PC gaming's longevity. Keeping it alive now means rebuilding the trust layer it was founded on, before the next poisoned mod finds it.

Sources

New to crypto? Read the crypto glossary, browse frequent questions, read our story, or explore the story archive.

← Back to Crypt0's News