Cybersecurity researchers have uncovered a widespread malware campaign that uses anime-themed desktop wallpapers to infect gamers with software capable of stealing cryptocy wallets, browser passwords, Steam accounts, and other sensitive data. The attack exploits Wallpaper Engine, one of Steam’s most popular desktop customization applications, by disguising malware as animated wallpapers distributed through the Steam Workshop. Researchers warn that some of the infected wallpapers were downloaded thousands—and in some cases tens of thousands—of times before being removed.
The discovery highlights a growing trend in cybercrime where attackers are abusing trusted platforms instead of relying on phishing emails or fake websites. Because the malicious files were hosted through Steam’s official community platform, many users assumed the downloads were safe, allowing the malware to spread rapidly among gamers and cryptocy holders.
According to cybersecurity firm Kaspersky, attackers targeted Wallpaper Engine’s “Application Wallpaper” feature, which allows wallpapers to run executable programs on a Windows computer. While the feature enables developers to create interactive wallpapers, calendars, mini-games, and other desktop applications, it also provides an opportunity for attackers to execute malicious code under the guise of legitimate content.
Rather than simply displaying animated backgrounds, the infected wallpapers secretly installed malware as soon as users activated them. In many cases, the wallpapers functioned normally, making it difficult for victims to realize their computers had been compromised.
Researchers identified multiple malware families hidden inside the wallpaper packages, including:
These programs were designed to steal cryptocy wallet credentials, browser passwords, saved login information, Steam session tokens, and other sensitive files. In some cases, attackers hijacked victims’ Steam accounts and used those compromised accounts to upload additional malicious wallpapers, helping the campaign spread even further.
Because many cryptocy wallets store credentials within browsers or desktop applications, infected users risked losing access to both gaming accounts and digital assets.
Many of the malicious wallpapers featured popular anime-style female characters, allowing them to blend naturally into one of Steam Workshop’s most popular content categories.
Researchers believe the visual style was intentionally chosen because anime-themed wallpapers consistently receive large download volumes from Wallpaper Engine users. The familiar appearance reduced suspicion while increasing the likelihood that gamers would install the files without carefully inspecting them.
Kaspersky noted that the campaign does not appear to be operated by a single hacking group. Instead, multiple independent threat actors were observed using similar techniques to distribute malware through the platform.
After receiving Kaspersky’s report, Valve removed the identified malicious wallpaper packages from Steam Workshop. However, researchers caution that new malicious uploads can appear at any time because Steam Workshop allows users to continuously publish new community content. Simply seeing a high download count or positive ratings should not be considered proof that a wallpaper is safe. Several infected files accumulated tens of thousands of downloads before they were detected and removed.
The campaign primarily targeted users in China and Russia, but infections were also identified in Germany, Singapore, Hong Kong, Vietnam, India, Canada, and several other countries.
Security researchers recommend several precautions for anyone using Wallpaper Engine or downloading community-created content through Steam:
These steps can significantly reduce the risk of malware infections and unauthorized account access.
Elon Musk's artificial intelligence company xAI has filed a federal lawsuit challenging Minnesota's landmark law banning AI-powered "nudification" technology, arguing…
Bitcoin climbed toward $65,000 as an unusual shift in traditional financial markets created one of the rarest conditions…
Hyperscale Data has sold 100 Bitcoin to accelerate development of its planned artificial intelligence campus in Michigan, sending shares…
A newly launched memecoin called PIPEDOG ($PIPEDOG) became the latest breakout token on Robinhood Chain, surging more than 140x within…
BNY, the world's largest custodian bank, is bringing one of its core financial businesses onto…
A bipartisan group of U.S. senators has reportedly reached a new compromise on the ethics provisions of…