The developer of People Playground published a fuller account of this month's Workshop malware incident on September 24, and it spells out what Valve did about it. Valve deleted every Workshop item containing C# code, and C# mods are now retired from the game permanently.

The sandbox game comes from Studio Minus, whose developer posts on Steam as mestiez. The recap follows a September 22 announcement titled "Bad event," which pulled the Workshop offline.
What the developer says happened
"I disabled it quite a few hours ago due to yet another malicious mod," the developer wrote in that first post. "This one is especially bad."
"A few users were infected with a piece of malware that was specifically designed for this game," it says.
It spread by uploading itself to the Workshop and inserting itself into existing popular mods. Subscribers to those mods would find them auto-updating the next time they launched the game.
From there, the developer says, the malware deleted personal files, vandalised the player's Steam account, and uploaded sensitive information back to the Workshop. Studio Minus attributes the opening to a .NET vulnerability that the game's own safeguards were meant to block. Malicious mods have hit other games the same way, as with the Minecraft mod malware that targeted saved passwords.

Who was affected, and what Valve removed
The window was narrow. Studio Minus lists five conditions that all had to be true for a player to be infected.
- Be connected to the internet
- Launch the game between 6 PM and 8 PM CEST on September 21, 2026
- Play on Windows
- Have auto-updates enabled, which is the default
- Be subscribed to at least one infected mod through the Workshop
"Valve has deleted all items containing C# code, all items that contained sensitive data, and everything uploaded or updated since September 21," the developer wrote.
On the studio's own site, the developer adds that Steam was told directly. Emails "were sent out to affected users shortly after," the page says.
"If you didn't receive an email, you were most likely not affected," the recap says.
What affected players should do now
Anyone who played between September 21 and September 24 is given five steps. Change the Steam password, enable Steam Guard two-factor authentication, and review account activity for unauthorised purchases or trades.
The last two are checking email for a message from Steam, and scanning the PC with updated antivirus software. The September 22 post also told players to change their Discord password as soon as possible.
One reassurance from that earlier post no longer stands. A line saying the malware does not steal passwords, tokens, cookies or other credentials is now struck through on the page rather than deleted, leaving the retraction visible.
The studio site adds nuance. It says the uploaded data "could've been used to log into the player's Steam account," but that so far this does not appear to have happened.
The harvested Discord data "appears to be unusable by the attacker," the same page says, because it was encrypted with a key held only on the victim's machine. Changing passwords remains sensible either way, given how routinely stolen logins turn up in breach databases.
C# mods are gone and Lua is the likely replacement
"C# mods have been deleted and will no longer be officially supported or hosted on the Steam Workshop," the developer wrote. Contraptions, the game's non-code creations, are unaffected by the policy change, though the developer warns some may still have been caught in Valve's sweep.
A replacement is planned. The developer intends to swap the modding system for "a dedicated, far safer scripting alternative that is not based on C#", as the recap puts it.
Asked which language, the developer answered in a Q&A on the same post. "Lua is by far the best candidate, but JavaScript is also an option", they wrote.
The build available now is safe for a blunt reason. It cannot run mods at all, according to the recap.
February's incident and what is still unconfirmed
The developer documented an earlier 2026 episode as well. On February 1 the Workshop went dark after "a malicious addon has spread itself throughout the Workshop."
That one was milder by the developer's own account. A February 3 post said the mod overwrote the player's own uploads, reset preferences, deleted contraptions and reset achievements.
The Workshop reopened on February 6 with new mod security measures, including a rule that mods no longer auto-update and need manual approval when their contents change. Steam Workshop libraries elsewhere have had their own scares, including reports of malicious items in the Wallpaper Engine Workshop.
The September 22 post carried 12,429 upvotes and 3,915 comments on Steam at the time of writing.
Everything known here about Valve's response comes from the developer, not from Valve. The recap says only that the Workshop "is likely to return," and that the developer does not know when or in what state. Checked on September 25, 2026, no newer post had followed, and the game's Workshop page still led with the September 22 warning instead of a browsable mod list.



Discussion (0)
Be the first to comment.