A threat actor called EncryptHub has compromised a game on Steam to distribute info-stealing malware to unsuspecting users downloading the title.

A few days ago, the hacker (also tracked as Larva-208), injected malicious binaries into the Chemia game files hosted on Steam.

Chemia is a survival crafting game from developer ‘Aether Forge Studios,’ which is currently offered as early access on Steam but has no public release date.

  • Apeman42@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    2 days ago

    Did they hack Steam, or the dev’s computer? Or is this the dev deliberately shoving malware into a cheap asset flip game?

    Of course Steam should do more to check what’s being uploaded, but the distinction feels important.

    • YMS@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      Article:

      It is unclear how EncryptHub managed to add the malicious files to the game project but one explanation could be an insider helping out. The developer of the game has not published any official statements on their game’s Steam page or on social media.