Affected Systems

Valve Steam Workshop users, specifically those using Wallpaper Engine application. All versions of Wallpaper Engine that integrate with Steam Workshop are potentially affected. Scope includes users downloading community-created wallpaper content.

Exploitation Status

Active campaign confirmed. Threat actors are actively distributing malware through malicious wallpaper packages on Steam Workshop. This is an ongoing social engineering attack leveraging legitimate platform infrastructure.

Business Impact

Organizations with Steam installed on workstations face risk of malware infection through user-downloaded content. The attack vector bypasses traditional download restrictions by using a trusted gaming platform. Potential for credential theft, ransomware delivery, or lateral movement depending on payload. Gaming software on corporate endpoints creates blind spots in security monitoring. No CVE assigned as this is a platform abuse issue, not a software vulnerability.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Block or monitor Steam Workshop domains (steamcommunity.com/sharedfiles) at web proxy and firewall if Steam is not business-critical
  • Audit endpoints for Wallpaper Engine installation and recent Steam Workshop downloads via software inventory tools
  • Enable application control policies to prevent execution of unsigned binaries from Steam directories (%PROGRAMFILES(X86)%\Steam\steamapps\workshop)
  • Review EDR/AV logs for suspicious process execution originating from Steam Workshop content folders
  • Educate users about risks of downloading community content from gaming platforms on corporate devices