:

WORDPRESS MALWARE HIDES IN STEAM PROFILES

AI DESK1 MIN READ
MON, JUN 1, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Nearly 2,000 WordPress sites have been infected with malware that uses Steam Community profile comments to conceal command-and-control communications, researchers discovered.

The campaign exploits Steam's social features as an unconventional infrastructure layer for malicious operations. Attackers hide C2 data in comments on compromised or attacker-controlled Steam profiles, allowing infected WordPress installations to retrieve commands while evading detection. This method bypasses traditional network monitoring since traffic to Steam appears legitimate. The malware likely gains initial access through vulnerable plugins or weak credentials on WordPress sites. Security researchers identified the infection pattern across a distributed set of WordPress installations. The use of Steam profiles demonstrates how attackers adapt to exploit trusted platforms for command distribution. WordPress site administrators should immediately audit active plugins, update to the latest versions, and enforce strong credentials. Security teams should monitor for unusual outbound connections to Steam Community domains from web servers.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

GrapheneOS, a privacy-focused Android fork, is on track to ship preinstalled on commercial devices within three years. The project has gained significant momentum in developer circles.

JUST NOWIndustry Desk

A Chinese-speaking threat actor has exploited vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to compromise 996 devices and steal over 18,500 database records from government systems.

JUST NOWSecurity Desk

The ShinyHunters extortion gang claims it breached FBI systems using a previously unknown Oracle PeopleSoft vulnerability, stealing sensitive data on employees and job applicants. The group also defaced the FBI's jobs website.

JUST NOWAI Desk

ShinyHunters claims to have breached the FBI and stolen personal information belonging to agents and job applicants. The alleged theft could expose agents and their families to extortion and counterintelligence threats.

2H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.