• Pika@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    edit-2
    11 days ago

    That would make sense, although I think it’s unlikely that it embeds itself into the mods. It would probably replace itself. Since in order to embed itself into the mod, it would have to know how the mod is made/structured but I guess it would be possible if it was able to completely replace the existing mods with the worm.

    edit: Yeah, a post-work summary was posted today, and it basically did exactly that, it replaces all workshop mods created by the user with a copy of the worm, which then spreads. Honestly, I feel like this is also a vulnerability on Steam’s behalf as well because I don’t see any realistic use case of why it shouldn’t require either a 2FA or some form of validation before pushing an update to the game, especially one that changes the entire mod out for something else.

    This one happened to be allowing C-sharp integration, which is how the original infection happened, because that allowed for compilation at runtime. However, this vulnerability could technically happen with any Steam Workshop-enabled game. It’s really concerning that there’s no check system in place. The Steam depot should not allow you to be able to do a full mod replacement using a session or with token.