Hackers have embedded malicious code into custom wallpapers within Valve's Wallpaper Engine, compromising user accounts and sensitive data. The campaign has been active since late 2025 according to researchers at Kaspersky. Attackers primarily targeted users in China and Russia through the application.
Security researchers uncover hidden code in user-uploaded desktop backgrounds that can steal accounts and sensitive data.
Valve distributes Wallpaper Engine on Steam as a tool for displaying animated desktop backgrounds. Users upload their own creations to a shared community workshop, which allows others to browse and install them directly. The app runs these files locally on the PC, granting the software access to system resources during playback.
Malicious wallpapers in this campaign contained hidden code that executed applications after installation. Infected files could steal Steam accounts and other sensitive information from affected machines. Kaspersky researchers identified the threat by analyzing suspicious user-uploaded content within the app ecosystem.
Security experts recommend verifying the reputation of wallpaper creators before installing their work. Users should also maintain active security software to detect unauthorized activity on their systems. The campaign highlights risks associated with running unverified community content on personal computers.
Source: DEXERTO



