Malware that can steal your Steam login details found in Wallpaper Engine and flagged by researchers
Table of Contents
Wallpaper Engine remains one of the most popular (non-game) applications on Steam, giving users the ability to customize their desktops with animated and interactive wallpapers. However, a recent security report has revealed that cybercriminals have been using the platform’s Workshop system to distribute malware, potentially putting thousands of users at risk.
According to researchers at Kaspersky, attackers have been hiding malicious software inside Wallpaper Engine workshop uploads for several months. The campaign reportedly began around late 2025 and has primarily targeted gamers, with a large number of victims located in China and Russia. However, users from several other countries have also been affected.
Users can upload .exe files to Wallpaper Engine on the Steam Workshop
What makes this issue particularly concerning is the way Wallpaper Engine works. While many wallpapers are simply animated images or videos, the application also supports “application wallpapers.” These are essentially executable (.exe) programs that run directly on a user’s PC as part of the desktop background. Because they function like normal Windows applications, they can also be used to execute malicious code.
Latest PC & Tech deals
- ASUS ROG Strix 34” QD-OLED XG34WCDG - was $7499 now $629
- Hisense 75" U8 Series ULED Mini-LED 4K TV - was $1,499 now $1,354
- ASUS ROG XG27AQNGV- was $999 now $649
- TCL 98 Inch Class QM8L - was $2,499 now $2,309
- CyberPowerPC Gaming PC (RTX 5060) - was $599 now $459
Prices correct as of August 20th, 2026.
Researchers discovered multiple infected wallpaper packages that contained hidden malware. In some cases, harmful files were placed directly alongside legitimate wallpaper content. In others, the malicious payload was hidden inside password-protected archives that could automatically extract and launch when the wallpaper was applied.
Once activated, the malware could perform several dangerous actions. Some samples were designed to steal Steam login information and hijack active user sessions. Attackers could then gain access to compromised accounts and use them to upload even more infected wallpapers, allowing the campaign to continue spreading through Wallpaper Engine’s Steam Workshop.
The report also found a wide range of malware families being distributed through these uploads. These included information stealers, remote access tools, cryptocurrency miners, ransomware, and other malicious software. Researchers believe multiple threat groups may have been using the same technique rather than a single organization operating the entire campaign.
Infected wallpapers are being cleaned up
The good news is that the identified malicious wallpapers have reportedly been removed from Steam Workshop. However, security experts warn that similar uploads could appear again in the future. Users should remain cautious when downloading content from unknown creators.
It’s not the first time we’ve seen action taken against malicious software distributed through Steam. Last month, Valve was forced to remove a free horror game that was hijacked by a hacker and unsuspectingly fitted with malware.
If you’ve recently installed application-type wallpapers from creators you don’t recognize, it may be worth running a full antivirus scan and even changing your Steam password as a precaution. It’s important to note that Wallpaper Engine itself is not infected, but this incident serves as a reminder that community-created content should always be downloaded carefully, especially when it has the ability to run executable code on your system.