Loading...

People Playground Hit By Second Malware Attack In 2025

Key takeaways

  • People Playground suffered a second malware attack on September 21, 2025, following an initial incident in February, with the latest threat significantly more dangerous than the first.
  • The September malware can erase data, extract Discord usernames, and automatically publish itself to spread further, though the developer expressed uncertainty about its complete scope.
  • The developer disabled Steam Workshop entirely and advised players to delete all mods and change important account passwords as a precaution.
  • Player backlash has been severe, with multiple users announcing permanent departure from the game due to security concerns.

People Playground, a physics simulation game on Steam that lets players conduct physics-based experiments on stick figure characters, has become the target of malicious activity twice within a single year. The game, which launched in 2019 and has accumulated hundreds of thousands of reviews, faced its latest security crisis on September 21 when developer mestiez discovered and disabled another malicious mod spreading through the Steam Workshop.

The September incident represents an escalation in both scope and potential harm compared to a similar attack that struck the game in February. This pattern of vulnerabilities has sparked concern within the player base, with some longtime users abandoning the title entirely over safety worries.

A Second Strike In One Year

On September 21, mestiez published an urgent warning to the community, describing the newly discovered malware as “especially bad.” The developer immediately disabled the Steam Workshop to prevent further damage, a drastic measure underscoring the severity of the threat.

Players who accessed the game during the early hours of September 21 received immediate guidance to delete all mods stored in their mods folder and refrain from launching the game until the developer announced it was safe to do so. This precautionary instruction signals confidence that the malware activated upon mod execution rather than through passive file presence, though mestiez offered limited technical detail.

Mestiez acknowledged uncertainty about the attack’s full scope in a public statement: “I can’t say with certainty what exactly happened or what this program did, but it’s not looking good.” The developer’s inability to fully characterize the threat added to player anxiety about the severity of the incident.

People Playground Hit By Second Malware Attack In 2025

The Malware’s Capabilities

Data Destruction and Harvesting

The malicious mod appears designed to accomplish multiple objectives beyond simple disruption. The malware erases data on affected systems, reads Discord usernames and other identifying information from users’ Discord accounts, and self-publishes additional mods to the Steam Workshop to perpetuate the infection vector. This self-replication mechanism transforms the malware into a spreading agent within the very platform meant to distribute legitimate user content.

What the Malware Does Not Steal

In an initial statement, mestiez clarified that the malware “DOES NOT steal your passwords, tokens, cookies, or other credentials. It will not hack you, but it’s a catastrophic piece of malware nonetheless.” However, the developer later deleted this reassurance and issued a revised warning suggesting that players change passwords for all important accounts to invalidate any session tokens that could have been included in the attack.

This reversal indicates either evolving understanding of the threat or caution superseding initial analysis. The contradiction between claiming no credential theft and then recommending universal password changes reflects the defensive posture appropriate to an incompletely understood threat.

Escalation From February

The February incident that struck People Playground earlier in 2025 appeared far less ambitious in scope. That malware primarily corrupted game files and modified mod lists, creating frustration but not posing broad system-level threats to affected users. The contrast between February’s relatively contained attack and September’s multi-vector approach suggests either a more sophisticated attacker or an escalating knowledge of People Playground’s community vulnerabilities.

Why the same game attracted two separate attacks within months remains unclear. Mestiez explicitly discouraged speculation, writing “This is entirely my responsibility, and we gain nothing from throwing around rumors or speculations.” The developer’s assumption of responsibility, while admirable for transparency, avoided explaining how the same attack vector struck twice or what systemic weaknesses enabled these specific incidents.

Developer Response and Community Action

Mestiez’s public handling of the crisis prioritized transparency and harm mitigation. The warning to players included clear instructions about mod deletion and deferring gameplay until an all-clear announcement. The developer’s admission of uncertainty about the malware’s exact function and effects contrasted with confident technical guidance about remediation steps.

Workshop Shutdown as Containment

The decision to disable the entire Steam Workshop rather than attempt selective mod removal demonstrates the difficulty of containing attacks through targeted moderation. A complete marketplace shutdown, even temporarily, acknowledges that individual mod identification and removal cannot be trusted to contain the threat. This nuclear option reflected the severity of the September attack and the inadequacy of partial measures.

Player Reaction and Community Impact

Community response reflected frustration and mistrust. The Steam update warning about the malware accumulated over 1,000 comments as players processed the second attack in months. Some users expressed surprise at the infrequency of public warnings, with one commenting “Crazy this is the first post even though there’s been several Malware mods pop up.”

Player retention faced immediate threats. Multiple comments indicated users abandoning the game permanently rather than risk future incidents. One user wrote “Other people like myself have already stopped playing and don’t plan to come back,” while another expressed disbelief at the recurrence: “Crazy this is the only game I’ve seen that has malware not once but TWICE in my time of owning it.”

The tone shifted from frustration to resignation in some quarters. Players acknowledged the impossibility of developer negligence while expressing unwillingness to continue engaging with what they perceived as an unsafe platform. The comment “I’m not gonna get all mad and rant, so ill keep it short. To the devs: this is SO not ok to have!” captured disappointment rather than fury, suggesting that extended exposure to these incidents had exhausted players’ benefit of the doubt.

The Broader Steam Workshop Vulnerability

People Playground’s repeated compromises point to structural problems within Steam’s modding infrastructure. The Workshop platform enables user-created content distribution with minimal friction, a design philosophy that prioritizes accessibility over pre-distribution security verification. Malicious actors can exploit this permissiveness to distribute harmful software under the guise of legitimate mods.

The gap between attack occurrence and effective community notification appeared problematic. Players noted that multiple malicious mods circulated before the developer’s official announcement, indicating either delayed detection or a lag in public communication. For a game where Workshop content integrates directly into the user’s local game installation and file system, this lag creates exposure windows.

The September incident underscores that indie developers operating on Steam rely on community moderation, user vigilance, and post-hoc threat identification rather than preventive platform-level controls. The economic incentive to maintain an open marketplace for creators conflicts with the security imperative to prevent distribution of harmful software. People Playground’s situation, while specific to that title, illustrates a tension built into Steam’s modding ecosystem that will persist as long as the barrier to publishing remains low, attracting creative contributors and malicious actors in equal measure.

Frequently Asked Questions

What is People Playground?

People Playground is a physics simulation game on Steam released in 2019 that allows players to conduct physics-based experiments on stick figure characters. The game has accumulated hundreds of thousands of reviews.

What did the September 21 malware do?

The malware erases data on affected computers, reads Discord usernames and identifying information, and automatically publishes new malicious mods to continue spreading. While it does not steal passwords, tokens, or cookies, the developer recommended players change important account passwords as a precaution.

What was the player reaction?

The developer's warning accumulated over 1,000 comments. Multiple players announced plans to permanently leave the game, citing safety concerns and the fact that this was already the second malware attack in 2025.

Written by
Ryan Cross

Ryan Cross is a video game journalist who has been covering the industry since the Xbox 360 era. He specializes in AAA game releases, studio news, and the business decisions behind the biggest franchises. Ryan has reviewed hundreds of games across every major platform and believes every game deserves an honest take — not a PR one.