Observed Signal · Jun 19, 2026 · Security Incident · Source: t3n · Impact: 3/5 · Sentiment: Negative
Steam Wallpapers Infected with Malware
Security researchers (Kaspersky) report that dozens of user-created wallpapers for the Wallpaper Engine on Steam have been found to contain malware since late 2025. Attackers packed malicious files inside archives (sometimes protected by passwords that were published with the wallpaper) so that animated wallpapers and minigames could execute foreign code on Windows and Android devices. Infections installed backdoors that fetched additional payloads to steal Steam login credentials, deploy ransomware, and run hidden crypto‑miners. Valve removed the identified wallpapers and suspended the associated accounts. Kaspersky and the article advise avoiding app-based wallpapers from Steam Workshop and using antivirus tools to detect and quarantine suspicious files.
A security incident on a major gaming/distribution platform (Steam/Wallpaper Engine) that enabled account compromise and distribution of multiple malware types; relevant for platform trust, user safety, and platform content-moderation practices.
Track Valve Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Kaspersky reported that dozens of Steam Workshop wallpapers (Wallpaper Engine) contained malware since late 2025.
- Malicious wallpapers used embedded archives (sometimes password-protected) to execute arbitrary code on Windows and Android systems.
- Observed payloads included backdoors, credential-stealers targeting Steam accounts, ransomware encryption, and hidden crypto‑miners.
- Attackers sometimes published passwords or instructions to prompt users to unlock archives and run the malicious content.
- Valve removed the malicious wallpapers from Steam and suspended the responsible accounts; users are advised to avoid downloading app-based wallpapers and to use antivirus software.
Connected Companies & Entities
3 Entities mappedRelated Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Steam fake games infected 8,000 PCs; FBI arrests suspect
Between May 2024 and February 2026, cybercriminals published seven fake games on Valve's Steam platform that concealed malware designed to harvest credentials and other sensitive data to access cryptocurrency wallets. The campaign infected nearly 8,000 PCs and allowed attackers to empty roughly 80 wallets, stealing about $220,000. The operators promoted the malicious titles via social media and bots to target high-value crypto holders; victims included Twitch streamer RastalandTV, who lost $32,000 and later died in March 2026. The FBI, working with affected gamers, traced stolen funds through Bitrefill vouchers and arrested a 21-year-old suspect in Florida. Authorities say the accused bought a Remote-Access Trojan for about $10,000 and faces charges including conspiracy to distribute malware, which carries potential prison terms of roughly 5–20 years.
FBI arrests man over Steam games that drained crypto
U.S. prosecutors say 21-year-old Florida resident Zyaire Wilkins uploaded malware-laden fake video games to Steam that infected users, stole credentials and drained cryptocurrency wallets. The FBI arrested Wilkins on July 14–15, 2026, and prosecutors allege he and unnamed co-conspirators published several malicious games over the past two years, infecting around 8,000 victims and hacking roughly 80 cryptocurrency wallets to steal at least $220,000 in crypto. The group allegedly marketed the fraudulent games via Discord, LinkedIn and Telegram. Federal agents executed a search warrant at Wilkins’ residence and seized laptops, phones and digital wallets. Valve (Steam’s maker) has removed multiple games previously found to contain malware; the FBI has asked victims to come forward to assist the investigation.
WordPress Plugins Infected with Backdoor
A security researcher, Austin Ginder, discovered that more than 30 WordPress plugins were modified to include a backdoor allowing attackers to inject malicious content into websites. The affected plugins — originally developed by an Indian team called WP Online Support and later sold in early 2025 to an anonymous buyer using the nickname “Kris,” who renamed the collection Essential Plugin — remained dormant until the backdoor was activated in early April 2026. Injected payloads reportedly loaded spam links, redirects, fake pages and crypto-related links from a remote server, and the injections were cloaked so only Google’s crawler could see them. Essential Plugin says the infected addons had over 400,000 installs; the extensions have since been disabled in the WordPress store. Ginder published a patch and a removal recommendation for site operators.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
