News

Steam Workshop Malware Hits People Playground Mods Again

Screenshot of a Steam community page for "Mecca Chameleon," featuring a colorful header, navigation sections, and a grid of game map items with thumbnails and creator usernames.
Big Brain
Big Brain
Published
9/23/2026
Read Time
5 min

People Playground's Steam Workshop is disabled after a second mod malware incident this year. Here is what the developer confirmed and how players can reduce risk.

Screenshot of a Steam community page for "Mecca Chameleon," featuring a colorful header, navigation sections, and a grid of game map items with thumbnails and creator usernames.

Image: windowscentral.com

Workshop support was pulled after a short but serious exposure window

People Playground has lost Steam Workshop support again after its developer disabled the feature over what it called “yet another malicious mod.” In a September 22 Steam news post cited by Rock Paper Shotgun and Cheat Code Central, the developer warned that anyone who played the ragdoll sandbox with mods enabled between 6 PM and 8 PM CEST on September 21, or 5 PM to 7 PM BST, should run an antivirus scan, delete all files in the game’s mods folder, and avoid opening the game until an official Steam announcement says it is safe.

That is the concrete player-facing emergency: a mod distributed through Steam Workshop was dangerous enough for the developer to remove Workshop access, tell users not to launch the game, and revise its own guidance as new risks became clearer. People Playground is a Steam sandbox built around experimenting on crash-test-dummy-style ragdolls, and like many physics sandboxes, its long tail depends heavily on player-made content. The immediate tension is obvious. The same mod pipeline that keeps a sandbox alive also became the route for a Steam mod malware incident serious enough to interrupt normal play.

Rock Paper Shotgun quotes the developer’s Steam post as saying, “You might have noticed the Workshop has disappeared again,” followed by the explanation that it had been disabled “due to yet another malicious mod.” The same post described this case as “especially bad.” For players, that wording matters because this was not framed as a suspicious file caught before impact. The developer issued direct instructions to people who had run the game with mods during a specific two-hour window.

What the developer says the malware could do

According to Rock Paper Shotgun’s report on the Steam post, the developer said the malware could permanently wipe “a considerable amount” of personal data, vandalize Steam configuration files, damage Steam Cloud data for other games, and publish personal information from a user’s Discord account to Steam Workshop. Cheat Code Central, citing the same Steam source and Rock Paper Shotgun’s reporting, repeats those stated risks and notes that Steam Cloud saves tied to unrelated games could be affected.

The password guidance changed in a way players should take seriously. Rock Paper Shotgun reports that Mestiez initially wrote that the malware “DOES NOT steal your passwords, tokens, cookies, or other credentials,” but later crossed that statement out. The revised guidance, as reported, tells users who want to be sure they are safe to change the passwords of important accounts to invalidate any session tokens that may have been included.

That correction is the key difference between ordinary cleanup advice and account-security triage. The confirmed developer warning does not say every affected player had credentials stolen. It does say the earlier reassurance was no longer something the developer was willing to stand behind. In practical terms, if you ran modded People Playground during the named window, the safe strategy is to assume cleanup is about both local files and account sessions, not only a bad mod sitting in a folder.

How Steam Workshop became the delivery lane

The confirmed distribution path in the reports is Steam Workshop: a malicious People Playground mod was available through the game’s Workshop support, and the developer disabled that support after discovery. The most important distinction is that this is a People Playground Workshop incident, not a confirmed platform-wide Steam game malware outbreak affecting every Workshop-enabled game. The affected guidance in the developer’s post is tied to People Playground players who ran the game with mods during the September 21 window.

Steam Workshop can make mod installation feel as low-friction as subscribing to an item and launching a game. That convenience is part of the risk profile here. If a game allows mods to run code or perform powerful file operations, the Workshop page can become the front door while the real danger executes locally when the game loads the content. The developer’s own instructions support that model: the warning is aimed at people who played with mods, not merely anyone who owns the game.

There are also claims beyond the developer’s public warning that should be treated as unverified unless confirmed by the studio or Valve. A 7MMO repost of PC Gamer’s coverage says a Reddit user who inspected the malicious Workshop mod claimed it could hijack a user’s Steam account to republish itself on Workshop along with personal information, destroy files for People Playground and other installed Steam games, and send slurs to Steam friends. That analysis may help explain how the outbreak spread, but it remains a third-party inspection claim in the supplied material, separate from the developer-confirmed guidance to scan, delete mods, change important passwords, and wait for an all-clear.

The second incident changes the trust calculation

This is not the first time People Playground has had to deal with Steam Workshop malware this year. Rock Paper Shotgun cites Kotaku as reporting that the current case is the second malware attack tied to a People Playground Steam Workshop mod within a year. In February, according to the same account, a malicious mod interfered with affected players’ files, contraptions folders, and mod lists, and the developer temporarily disabled the Workshop then as well.

A single malicious upload can be dismissed by a community as bad luck. A second shutdown in the same year is a different strategic problem for a mod-heavy sandbox. Every future Workshop item now has to be judged against a repeated failure mode: can players trust that the game’s mod pipeline is safe enough to use, and can the developer restore that trust without removing the very systems that make the game expandable?

The developer has avoided naming a culprit. Rock Paper Shotgun reports that Mestiez said there is no value in speculating about who released the malware and wrote, “This is entirely my responsibility, and we gain nothing from throwing around rumours or speculations.” That statement narrows the story in a useful way. The unresolved issue is not who the community can accuse today. It is whether People Playground’s mod architecture and Workshop process can be made resilient enough that a third incident is less likely.

Mod support may not return on the old terms

The sharpest forward-looking question is whether People Playground can safely keep the same mod model. A 7MMO repost of PC Gamer’s reporting says Studio Minus released a new build of People Playground that prevents mods from running and, citing the game’s Discord, said Workshop and mod support would return only if “mods are fundamentally safe to run,” a condition the repost says “might never happen.” Because that detail is presented through a forum repost and Discord citation in the supplied material, it should be read as reported status rather than a Valve storefront listing or patch note reproduced in full here.

The same 7MMO text cites a blog post from the game’s primary developer, zooi, describing People Playground as a “technical hellscape” and saying it is technically impossible to properly sandbox mods in their current state. It also quotes the developer as calling the security situation a “hopeless arms race.” If accurate, that context explains why the current response is harsher than simply removing one item from Workshop. The risk is structural: if mods can reach sensitive files or account-adjacent data, moderation after upload may always lag behind the damage.

For players, that means the return of Workshop support is not only a content-availability question. It is a risk-management question. A sandbox community wants new maps, contraptions, scripts, and toys. A developer facing repeat malware incidents has to decide whether preserving that ecosystem is worth the exposure, or whether modding needs to be rebuilt, restricted, or suspended until the attack surface changes.

Safer steps before downloading or launching mods

If you played People Playground with mods between 6 PM and 8 PM CEST on September 21, follow the developer’s reported instructions first: run an antivirus scan, delete the contents of the game’s mods folder, and do not reopen People Playground until the developer posts on Steam that it is safe. Because the developer revised its statement about credentials and session tokens, changing passwords for important accounts is also the cautious path, especially for accounts connected to Steam, Discord, email, and other services that could be used to recover or compromise additional accounts.

If you were not in the named window but use People Playground mods, the safest move is patience. Do not assume a Workshop item is safe because it has a familiar thumbnail, a high subscriber count, or a recent upload date. The supplied reports do not provide a clean all-clear, a full technical postmortem, or a confirmed timeline for restored mod support. Until the developer says otherwise on Steam, treating modded play as unavailable is the least risky option.

For Steam Workshop safety more broadly, the lesson is to treat mods as software, not decoration. Before downloading mods for any game, check the game’s official Steam news feed for active warnings, look for recent developer statements about Workshop status, avoid reuploaded files during an outbreak, and keep security software active before launching a newly modded setup. Those steps do not guarantee protection from mod malware, but they align with the response the People Playground developer is asking affected users to take now.

There is no confirmed evidence in the supplied reports that every Steam Workshop game is unsafe today. There is clear evidence that People Playground has suffered a second Workshop-linked malware incident this year, that the developer considered the latest mod severe, and that affected players have cleanup work to do before they return. In a mod ecosystem, convenience is part of the value. After this incident, verification has to be part of the routine.

Share: