News report
People Playground Disables Workshop After New Malware Incident
People Playground has disabled its Steam Workshop and mod support after a new malicious-mod incident. The developer warns some September 21 players to scan their PCs and remove mods.
On this page
People Playground has shut down its Workshop again
People Playground developer mestiez has disabled the game’s Steam Workshop after another malicious mod incident. The warning is unusually specific: players who had mods installed and opened the game on September 21 between 18:00 and 20:00 CEST were told to run an antivirus scan, delete their installed mods, and avoid launching the game until the developer says it is safe.
The developer’s investigation was still incomplete when the warning was issued. Reported effects include deletion of personal data, damage to Steam configuration or Steam Cloud data for other games, collection of a Discord username and other identifying information, and republishing through the Workshop. Those are developer-reported observations, not a complete independent forensic analysis, so the exact payload and full exposure should be treated as unsettled.
The practical response depends on whether you launched the game
The developer’s warning centers on running People Playground with mods during the identified September 21 window, not merely owning the game or having it installed. Players matching that condition should follow the developer’s current guidance: remove the mods, scan the PC, and leave the game closed until a new safety announcement appears.
For potentially affected systems, changing passwords for important accounts from a known-clean device is a reasonable precaution because it can invalidate some existing sessions. Users should also inspect Steam account activity and avoid relying on a clean quick scan as proof that no files or account state were altered. At the same time, there is not enough verified evidence to claim that every player in the time window had credentials stolen or suffered the same damage.
This is the second major People Playground Workshop incident this year
People Playground had already disabled its Workshop in February after a malicious add-on spread by overwriting users’ own Workshop uploads. The February incident was documented as resetting preferences and achievements and deleting contraptions and other People Playground data. The Workshop later returned with additional safeguards, including manual approval when mod contents changed.
The September incident is therefore important beyond a single bad upload. It shows that executable game mods can create a much wider trust boundary than ordinary cosmetic Workshop content. Steam distributing a Workshop item does not by itself make arbitrary code inside a game’s mod environment safe; the effective security boundary also depends on what the game’s mod loader permits that code to access.
What remains unknown
There is no public CVE, complete vendor forensic report, or independently verified list of every affected mod and payload behavior at the time of writing. Reports from users and community reverse engineering can help investigators, but they should not be promoted to confirmed facts until the developer, Valve, or a credible security analysis establishes them.
The next useful update will be the developer’s all-clear and an explanation of what technical restrictions are being added before mod support returns. Until then, the safest interpretation is narrow: a serious malicious-mod incident occurred, the Workshop was disabled, a defined group of recent players received remediation guidance, and the full impact is still under investigation.
Sources
Primary and technical sources
These sources support the reporting and analysis above. Current stories are updated when later evidence materially changes the facts.