Guess we’re going to get another round of Mr. Beast scams from compromised Discord accounts soon.
I don’t own this game or project or whatever it is, but I’m confused. How does a mod getting hacked on a workshop make it so every player that’s on the workshop has a virus?
- Patient Zero downloads the virus.
- Virus embeds itself in any mods Patient Zero uploaded to the Workshop.
- Anyone who subscribes to any of Patient Zero’s mods auto-updates with the virus.
- When these people launch the game, the mods they uploaded are also infected the virus.
- And so on and so on until everyone is infected.
That would make sense, although I think it’s unlikely that it embeds itself into the mods. It would probably replace itself. Since in order to embed itself into the mod, it would have to know how the mod is made/structured but I guess it would be possible if it was able to completely replace the existing mods with the worm.
edit: Yeah, a post-work summary was posted today, and it basically did exactly that, it replaces all workshop mods created by the user with a copy of the worm, which then spreads. Honestly, I feel like this is also a vulnerability on Steam’s behalf as well because I don’t see any realistic use case of why it shouldn’t require either a 2FA or some form of validation before pushing an update to the game, especially one that changes the entire mod out for something else.
This one happened to be allowing C-sharp integration, which is how the original infection happened, because that allowed for compilation at runtime. However, this vulnerability could technically happen with any Steam Workshop-enabled game. It’s really concerning that there’s no check system in place. The Steam depot should not allow you to be able to do a full mod replacement using a session or with token.
Depending on the system it is just one more full for the engine
It looks like it was one malicious item on the workshop, not necessarily the whole workshop. However, that one malicious item will uploaded your credentials to the People Playground Workshop. So they remedied it temporarily by disabling the entire workshop, including all legit mods, to prevent user credentials from being uploaded.
EDIT: I assume they are asking everyone who logged in during the 21st to run antivirus because it was trojan. Originally a legit mod that turned malicious after an update and all subscribers got the “updated” virus.
Yeah, that’s how I took it, but the developer acted like every system that was on the workshop was infected. They never listed a mod that caused the issue and instead just issued a blanket statement of this is what happened. It’s very weird.
Interesting…
I was incorrect.
It was closer to a worm. The virus infected local mods, and uploaded itself to the workshop alongside your credentials.
I guess that means any workshop creator who gets infected would further spread the virus because the virus automatically updated the creator’s workshop items with the infection.




