When a Game Mod Becomes a Worm: Steam Workshop Delivers Malware to the Same Game Twice

Summary
On 21/09/2026 a malicious mod was uploaded to the Steam Workshop for People Playground, a physics sandbox game with a very large modding community. The mod did not just destroy data — it self-replicated, using the victim's own Steam session to republish copies of itself to the Workshop, turning every infected player into a new distribution point.
This was the second Workshop malware outbreak for the game in 2026. This time the developer went beyond disabling the Workshop and shipped a build that blocks mods from running at all, saying mod support would only return if mods are "fundamentally safe to run" — something they suggested "might never happen."
For a SOC, the lesson is not about one game. It is that a high-trust user-content distribution channel still delivers arbitrary executable code to an endpoint, and that code runs with the full privileges of the logged-in user.
Priority actions:
Identify machines in your organization with mod-capable games installed, especially machines shared between work and personal use, and treat them as endpoints running unvetted code.
Tell users who ran modded People Playground around 21/09 to change passwords and sign out of all Discord sessions.
What Happened
The infection window was narrow. Per the developer, the malicious mod was active roughly between 18:00 and 20:00 CEST on 21/09/2026.
On 22/09, developer mestiez disabled the Steam Workshop and issued a public warning. Studio Minus then shipped an update blocking mod loading outright.
The developer's initial statement said the mod did "not steal your passwords, tokens, cookies, or other credentials." That line was later removed, and users were advised to change their Discord and all important account passwords immediately.
What the Malware Did
Based on the developer's statements and community analysis, the mod:
Permanently wiped a considerable amount of personal data on the victim's machine.
Vandalized Steam configuration and Steam Cloud data for other games, so damage was not confined to the infected title.
Collected Discord usernames and other identifying information.
Sent offensive messages to the victim's Steam friends list.
Published copies of itself to the Workshop, embedding the victim's personal information in the redistributed version. That last behavior is both the propagation mechanism and a form of public humiliation.
The Worm Mechanism
This is the technically interesting part, even if games are not your concern.
People Playground mods are assemblies loaded directly into the game process, so they inherit everything the user running the game can do: read and write files, make network calls, and critically, use the logged-in Steam session.
With that session, the mod can do what ordinary malware would need its own infrastructure for: publish Workshop content as the victim. The consequences:
No distribution server needed. Valve's infrastructure does the delivery.
No email filter or proxy to defeat. Users download it themselves.
Every victim becomes a new source, and each new copy carries the reputation of a real account with real playtime. The campaign sustains itself with no further attacker involvement. It is the propagation model of 2000s email worms, with a content distribution platform in place of the address book.
Compared With the February 2026 Incident
The same game was hit in February 2026 by a worm referred to as FPS++. The September variant is named FPS++++.
February 2026 (FPS++) |
September 2026 (FPS++++) |
|
|---|---|---|
| Damage scope | Game files only | Reaches beyond the game into personal data |
| Data destroyed | Saves, achievements, control settings, custom maps and contraptions | Personal data, Steam configuration, other games' Steam Cloud data |
| Information collection | Not reported | Discord usernames, identifying information |
| Account abuse | Self-replication | Self-replication, messages to Steam friends, victim data embedded in redistributed copies |
| Response | Workshop temporarily disabled | Workshop disabled and mods blocked entirely |
The developer described the September incident as considerably more dangerous, primarily because it left the game's own file scope.
The Root Problem: Mods Cannot Be Sandboxed
Developer zooi's own comments are the most candid part of this story. He called the game a "technical hellscape", said sandboxing mods in their current state is "technically impossible", and described earlier security efforts as a "hopeless arms race".
That is not an excuse; it is an accurate description of the architecture. When a mod is native or managed code running inside the game process, there is no privilege boundary between the mod and the rest of the machine. Any moderation layered on top is content filtering, and content filtering always runs behind the attacker.
Studio Minus's final choice — disabling mod execution entirely — is the right security decision, at the cost of the game's signature feature.
Not Just One Game
People Playground is not alone. The 2026 run of Steam user-content incidents includes:
February 2026 — People Playground: the
FPS++worm wiping saves and user-created content.April 2026 — Project Zomboid: Workshop mods found carrying obfuscated code.
June 2026 — Wallpaper Engine: wallpaper packs containing malware.
July 2026 — Meccha Chameleon: malicious maps that led to victims' Discord accounts being compromised.
September 2026 — People Playground: the
FPS++++worm covered here. Five incidents across four titles in eight months points to an attack model being worked systematically, not a run of isolated events. The common ingredients: an open platform, millions of users, automated moderation, and a community with high mutual trust.
Analysis
Incident communication is the hardest part to get right. The developer saying "no credentials were stolen" and then pulling that line and advising password changes is a familiar sequence: early information is always incomplete. The takeaway for IR teams is to avoid statements about damage scope before analysis is done — and where an early statement is unavoidable, to say "not yet determined" rather than "did not happen".
The Workshop is a high-trust delivery channel. Users download a mod in a completely different mindset from opening an email attachment. No browser warning, no SmartScreen, no gateway filter. An attacker can also build reputation first with a few harmless mods and slip malicious code into an update — something report-driven moderation rarely catches in time.
For a SOC, a machine with games on it is not a recreation issue. It is an endpoint executing code from an unvetted source with the logged-in user's privileges. If that machine also holds work data or has internal tools signed in, the attack surface is the same whether the code arrived from the Workshop or from an attachment.
Discord tokens are the more worrying link, not game data. Many engineering teams run on Discord. A stolen token lets an attacker read internal channels and post as the victim — exactly what happened in the Meccha Chameleon case in July.
Data is still missing. There is no independent technical analysis, no victim count, and no public indicators (no hashes, domains or webhooks). This story is useful for understanding the attack model, not yet for building specific detection rules.
Relevance to Vietnam
Machines shared between work and leisure are common. In many SMEs, one personal laptop serves both. A data-wiping worm on that machine can take unsynced work documents with it.
Discord is used for work across many Vietnamese engineering teams and developer communities. Losing a Discord token is not just a personal account problem.
Habits around downloading mods and cracked content widen the surface further. Users are already conditioned to dismiss warnings when installing game content.
BYOD is widespread but lightly managed. Plenty of organizations allow personal machines to access email and documents with no application control policy at all.
Recommendations
For users who ran modded People Playground around 21/09: delete the mod folders, run a full antivirus scan, change passwords on important accounts, and sign out of all sessions on Discord and Steam to invalidate any stolen tokens.
Separate work and gaming environments. Where a separate machine is not possible, at minimum do not sign into internal tools or work email on a machine used to install game mods.
Apply application control on corporate machines. If games and launchers are not needed for work, block them via allowlist rather than relying on user judgment.
Monitor behavior instead of waiting for IOCs. A game process writing across many user directories, touching Discord's application data, or opening unusual outbound connections all warrant investigation — and none of those rules depend on this particular worm.
Enable MFA and review permissions on work Discord servers, limiting who can create invites or change channel settings, to contain the damage when one account is taken over.
Back up personal and work data off the machine. Against a worm with a wiping function, backups are the only control that does not depend on detecting the malware.
References
Studio Minus — incident statement and
FPS++++worm analysis (09/2026): https://studiominus.nl/ppg-september-incidentPC Gamer (Lincoln Carpenter) — Steam game disables mods after facing its second Workshop malware outbreak this year (23/09/2026): https://www.pcgamer.com/games/sim/steam-game-disables-mods-after-facing-its-second-workshop-malware-outbreak-this-year/
Dexerto — Steam game shuts off mods after malware hijacks accounts and sends slurs to players' friends: https://www.dexerto.com/gaming/steam-game-shuts-off-mods-after-malware-hijacks-accounts-and-sends-slurs-to-players-friends-3412254/
AllKeyShop — If you played People Playground this week, you may need a password reset: https://www.allkeyshop.com/blog/people-playground-malware-password-reset-warning-news-n/
Gamers Universe — People Playground Gets Hit by Malware for the Second Time in a Year: https://gamersuniverse.eu/en/people-playground-hit-by-malware-again
The Tech Edvocate (Matthew Lynch) — Devastating Steam Malware Attack Strikes Popular Game Twice in a Year (24/09/2026): https://www.thetechedvocate.org/devastating-steam-malware-attack-strikes-popular-game-twice-in-a-year/





