126
submitted 5 days ago by sundray@lemmus.org to c/games@lemmy.world

Key takeaways

  • Valve removed Beyond The Dark after malware allegations surfaced.
  • The malicious payload allegedly stole passwords, browser data, and crypto wallet information.
  • Attackers reportedly hijacked an existing Steam game instead of publishing a new one.
  • The malware hid inside a modified UnityPlayer.dll file.
  • Anyone who installed the game should run antivirus scans and change passwords immediately.
top 22 comments
sorted by: hot top new old
[-] Corngood@lemmy.ml 25 points 5 days ago

I'd rather not use flatpack, but I really should figure out better sandboxing. Not just for games, but for supply chain attacks, etc.

It's kind of nuts that a game has access to my browser profile and all sorts of other stuff in ~.

[-] DampCanary@lemmy.world 2 points 5 days ago

I know firejail nicely packs my Firefox & co. to only have access to select few /home/ sub-dirs

[-] Mordikan@kbin.earth 2 points 3 days ago

This is what I do as well. Process inheritance helps prevent any game that Steam runs from misbehaving outside it's whitelisted directories.

[-] DampCanary@lemmy.world 2 points 2 days ago

Its reasuring, knowing that any potentially spawned process is also sandboxed to the same environment and while it doesn't isolate (in terms of e.g. Docker) it does contain it to less risky (with correct set up) part of the system.
A big bonus to it, is that it provides basic profile versions for the whole plethora of programs which can be simply expanded/adjusted with custom user profile.

[-] magikmw@piefed.social 1 points 5 days ago* (last edited 5 days ago)

Selinux should help with this, but by default all 'non-server' apps can just access anything across the user's home. Maybe I should look into this. Hmmmm.

Edit: then again, steam games usually run via wine, using a simulated windows filesystem... Maybe they are isolated already? I really should look into this.

[-] tomalley8342@lemmy.world 14 points 5 days ago

Maybe they are isolated already? I really should look into this.

No, the Z drive in wine maps to your linux file system.

[-] Mordikan@kbin.earth 4 points 4 days ago

Imagine being a dev and having this happen to you. Still, MFA is a thing.

[-] Katana314@lemmy.world 3 points 5 days ago

Long ago when Linux was a complete underdog (0.001% of users or something) it was touted as being vastly more secure than Windows, and that was probably true. But, convenience always battles with security in adverse ways, and Steam does aim to be very convenient.

I remember for a time any Xbox-app game would prop up a UAC permissions dialog each time you'd newly installed a game. Those apps are also un-moddable due to package signing. It was very annoying, but part of me thought "...Theoretically, Steam should be doing at least something like this."

[-] Rai@lemmy.dbzer0.com 2 points 5 days ago

The “FAQ” on this article feels like they just took an LLM sum marry and added it to the bottom hahaha

[-] SaltySalamander@fedia.io 3 points 4 days ago
[-] Rai@lemmy.dbzer0.com 1 points 4 days ago

You entered seen a mobile phone autocorrect mistake before, I take it?

[-] SaltySalamander@fedia.io 6 points 4 days ago
[-] Rai@lemmy.dbzer0.com 2 points 4 days ago

I’ll read what I type before sending when I’m dead

[-] ArcaneSlime@lemmy.dbzer0.com 2 points 4 days ago

Locks like they make alot of them.

[-] stephen01king@lemmy.zip 3 points 4 days ago

You should re-read your comment before posting them.

this post was submitted on 22 May 2026
126 points (99.2% liked)

Games

48638 readers
1787 users here now

Welcome to the largest gaming community on Lemmy! Discussion for all kinds of games. Video games, tabletop games, card games etc.

Rules

1. Submissions have to be related to games

Video games, tabletop, or otherwise. Posts not related to games will be deleted.

This community is focused on games, of all kinds. Any news item or discussion should be related to gaming in some way.

2. No bigotry or harassment, be civil

No bigotry, hardline stance. Try not to get too heated when entering into a discussion or debate.

We are here to talk and discuss about one of our passions, not fight or be exposed to hate. Posts or responses that are hateful will be deleted to keep the atmosphere good. If repeatedly violated, not only will the comment be deleted but a ban will be handed out as well. We judge each case individually.

3. No excessive self-promotion

Try to keep it to 10% self-promotion / 90% other stuff in your post history.

This is to prevent people from posting for the sole purpose of promoting their own website or social media account.

4. Stay on-topic; no memes, funny videos, giveaways, reposts, or low-effort posts

This community is mostly for discussion and news. Remember to search for the thing you're submitting before posting to see if it's already been posted.

We want to keep the quality of posts high. Therefore, memes, funny videos, low-effort posts and reposts are not allowed. We prohibit giveaways because we cannot be sure that the person holding the giveaway will actually do what they promise.

5. Mark Spoilers and NSFW

Make sure to mark your stuff or it may be removed.

No one wants to be spoiled. Therefore, always mark spoilers. Similarly mark NSFW, in case anyone is browsing in a public space or at work.

6. No linking to piracy

Don't share it here, there are other places to find it. Discussion of piracy is fine.

We don't want us moderators or the admins of lemmy.world to get in trouble for linking to piracy. Therefore, any link to piracy will be removed. Discussion of it is of course allowed.

Authorized Regular Threads

Related communities

PM a mod to add your own

Video games

Generic

Help and suggestions

By platform

By type

By games

Language specific

founded 3 years ago
MODERATORS