Steam Workshop Hit by Malware Again: People Playground Disables Mods Permanently?
Baca dalam 60 detik
- Studio Minus menonaktifkan dukungan Steam Workshop untuk People Playground setelah serangan malware kedua dalam setahun.
- Mod berbahaya tersebut diduga mencuri data akun Steam, merusak file game, dan menyebarkan pesan kasar ke daftar teman.
- Insiden ini menyoroti risiko keamanan platform modding terbuka seperti Steam Workshop yang juga berdampak pada gamer Indonesia.

Studio Minus, the developer of the sandbox game People Playground, was forced to shut down Steam Workshop support after detecting a malicious mod that infiltrated the game. The decision was announced through a Steam update on 22 September, marking the second malware incident to hit the game this year.
In its statement, Studio Minus called the mod "extremely dangerous malware" and immediately released a new version of People Playground that prevents any mod from running. Workshop and mod support will only be re-enabled if "mods are fundamentally safe to run"—a condition that, according to the developer, "may never be met."
A Reddit user who investigated the malicious mod claimed that it hijacked victims' Steam accounts to redistribute itself along with users' personal information, deleted People Playground files and other installed Steam games, and sent abusive messages to victims' friends lists. Although it initially stated that the infected mod "does not steal passwords" or other credentials, Studio Minus later urged People Playground users to immediately change their Discord passwords and those of "all important accounts."
This incident is not an isolated case. Throughout 2024, at least three other games were reported to have been hit by malware through Steam Workshop: a malicious mod for Project Zomboid appeared in April, a virus disguised as an anime character in Wallpaper Engine in June, and an infected Meccha Chameleon map resulted in its Discord server being hacked in July. The pattern points to a systemic vulnerability in the relatively open mod distribution platform.
"This is the double-edged sword of Steam's relatively open publishing platform. We get to enjoy many games from small developers—but they cannot always offer the same software security guarantees as their more established peers."
For gamers in Indonesia, this risk is not merely international news. Steam is the largest game distribution platform in Indonesia, and many players rely on mods to enrich their gaming experience. Malware attacks not only threaten personal accounts but can also spread to broader networks if the device is used for work or to access financial services. Cybersecurity awareness among Indonesian gamers remains low; surveys show that most users do not enable two-factor authentication on their Steam accounts.
Moreover, this incident highlights weak oversight of user-generated content on gaming platforms. Valve, as the owner of Steam, has not issued an official comment regarding this series of attacks. However, public pressure may force it to tighten mod curation or provide more sophisticated malware scanning tools. Meanwhile, indie game developers who rely on mods to extend the lifespan of their games are in a difficult position: closing the Workshop means losing appeal, but leaving it open means risking their reputation and user security.
Going forward, the big question is whether Valve will step in to regulate the Workshop ecosystem more strictly, or whether each developer must fight alone against constantly evolving malware. Without collective action, gamers—including those in Indonesia—will continue to be easy targets.



