Patreon Logo Support us on Patreon to keep GamingOnLinux alive. This ensures all of our main content remains free for everyone. Just good, fresh content! Alternatively, you can donate through PayPal Logo PayPal. You can also buy games using our partner links for GOG and Humble Store.
We use affiliate links to earn us some pennies. Learn more.

Oh dear. People Playground from mestiez / Studio Minus recently had a major problem with malware pretending to be a mod in the Steam Workshop.

I would say this is a reminder to be careful on what you're downloading - but these types of things are quite difficult for normal users to spot until it's too late. For many it was too late, since this wiped away various things. On Windows at least, it's not clear if it affected Linux (with the game run via Proton).

In PSA posted on Steam the developer said on February 1st they disabled the Steam Workshop, and a few days later released a security update to prevent the issue in future and as of February 6th they have enabled the Steam Workshop once again.

The developer has a forum post on Steam that goes over various details of what the malware did, here's an excerpt from it:

to put it simply: a mod was uploaded "FPS++" which turned out to be a worm malware.

here is a list of EVERYTHING the mod does (since people were asking to read the code themselves, which i will not share myself as its a security risk.) once the game is launched with the mod enabled:

  1. silently votes and favorites the mod (FPS++)
  2. scans every workshop item you published, edits all of them silently, reuploads content, changes descriptions (1 in 2 chance to add "optimized" to the new mod's description), adds tags, upvotes and favorites all of those items.
  3. creates and uploads a brand-new public workshop item under your account. copies the mod’s files, title, thumbnail, and description into it. upvotes and favorites that new item too.
  4. resets your steam stats for the game, such as achievements. your playtime is untouched. also deletes configs, control schemes, stats, caches, maps, contraptions, and prefs.
  5. wipes mod json files and empty mod folders.
  6. disables every other mod except itself and one hardcoded name.
  7. makes fps cap 10000, disables shady code protection.
  8. makes it look like the mod is working by multiplying the fps counter, lmao.


everything—except achievements—are completely gone and unrecoverable after youve been infected. if you want your achievements back, you can use 3rd party tools that i will not link in order to spoof the game into thinking you had the achievements you previously had. although this is technically cheating, so is your achievements being deleted after a ♥♥♥♥ decides to delete them all.

The Steam Workshop is a place where you can find some really amazing work from the community, but such a system is clearly open to abuse of different forms. Like back in 2022 the city-builder Cities: Skylines had an issue with multiple mods noted in a Reddit post, but a later announcement from the Cities: Skylines team clarified there were other issues that led to their removal. Then in 2024 a mod for Cities Skylines 2 as confirmed by Paradox Interactive was subject to a DLL hijacking attack.

Steam as a whole has been hit by malware directly in games multiple times too, with Valve announcing changes in November 2023 to hopefully prevent some of the issues.

In December 2023 we also had the developers of the standalone Slay the Spire mod Downfall announce a security breach where a malicious upload was able to overtake the game completely due to their Steam and Discord accounts being hijacked.

There's probably more cases but it really shows you can never be too careful.

Article taken from GamingOnLinux.com.
9 Likes
About the author -
author picture
I am the owner of GamingOnLinux. After discovering Linux back in the days of Mandrake in 2003, I constantly checked on the progress of Linux until Ubuntu appeared on the scene and it helped me to really love it. You can reach me easily by emailing GamingOnLinux directly.
See more from me
All posts need to follow our rules. Please hit the Report Flag icon on any post that breaks the rules or contains illegal / harmful content. Readers can also email us for any issues or concerns.
6 comments

TheSHEEEP 10 hours ago
... but why?
Usually, malware has a specific purpose, monetary or data gathering or disrupting infrastructure.

This just messes with your mods and steam stats for a title.
Very annoying especially for modders, but beyond that I don't understand the motivation here.
Liam Dawe 10 hours ago
User Avatar
I don't think we will ever understand why some people do stupid annoying things like this. Some people to do just for kicks, because they can.
MiZoG 9 hours ago
They're doing it for "educational" purposes
There must be something like a hacker's school.
Teacher assigns a task as a schoolwork on a Friday morning
"Come by next Monday with a new infested AUR repo.
100 downloads get you an A"
I guess this is an assignment for primary school grades.
Infecting Steam Workshop... we're not talking about some hacker's academy, are we? 🤔
It is just newbies trying their powers till they get ready for more advanced endeavours.
Mountain Man 7 hours ago
User Avatar
Quoting: TheSHEEEP... but why?
Usually, malware has a specific purpose, monetary or data gathering or disrupting infrastructure.

This just messes with your mods and steam stats for a title.
Very annoying especially for modders, but beyond that I don't understand the motivation here.
Trolling.
Caldathras 2 hours ago
Oh dear, indeed. Does this malware only affect People Playground or does it infect all installed Steam games that are using Steam Workshop?
Linux_Rocks 1 hour ago
User Avatar
Quoting: TheSHEEEP... but why?
Usually, malware has a specific purpose, monetary or data gathering or disrupting infrastructure.

This just messes with your mods and steam stats for a title.
Very annoying especially for modders, but beyond that I don't understand the motivation here.
External Media: You need to be logged in to view this.
While you're here, please consider supporting GamingOnLinux on:

Reward Tiers: Patreon Logo Patreon. Plain Donations: PayPal Logo PayPal.

This ensures all of our main content remains totally free for everyone! Patreon supporters can also remove all adverts and sponsors! Supporting us helps bring good, fresh content. Without your continued support, we simply could not continue!

You can find even more ways to support us on this dedicated page any time. If you already are, thank you!
Login / Register