Proprietary 2023-12-25 · 0 days ·Credential Theft, Data Theft

Downfall Steam build carried Epsilon

A compromised Table 9 Studio account replaced the standalone Steam build of Downfall with Epsilon Stealer on Christmas Day 2023.

Story

Downfall was not a poisoned Steam Workshop mod. It was the standalone Steam package for a major Slay the Spire fan expansion. On December 25, 2023, a breached developer account let the attacker replace the packaged game on the public Steam branch.

The replacement did not behave like Downfall. Players who launched the affected build saw a Unity library installer prompt. That prompt was the visible edge of Epsilon Stealer, which targeted browser credentials, cookies, payment data, Discord and Steam material, Telegram data, and files with password-like names.

The distinction between standalone and Workshop mattered. Players who used the Steam Workshop version of the Slay the Spire mod were not in the same distribution path; the compromised artifact was the standalone app build that Steam delivered as the game package.

Table 9 Studio said the exposure window was brief, roughly 12:30 to 1:30 p.m. Eastern on December 25, and affected the standalone Downfall branch, not the Workshop path. The developer knew of three affected users at disclosure time, but any player who launched during the window was told to scan the system and rotate important credentials.

The incident is included because it shows the same supply-chain shape as larger software compromises at a smaller scale: compromise the publisher account, replace the trusted artifact, and let a normal update or install path put credential-stealing code on user machines.

Affected Artifacts

app/1865780

steam · store.steampowered.com · Binary Archive
Observed
2023-12-25
Compromised Versions
Unknown
Fixed
Not listed
Evidence
distribution: store.steampowered.com/app/1865780/Downfall__A_Slay_the_Spire_Fan_Expansion, mirror: steamcommunity.com/app/1865780/discussions/0/4034727291141682949, malware: Epsilon Stealer, observable: Unity library installer prompt appeared when the replaced build was launched. , +2 more
  • The official developer post described the affected channel as the main branch of standalone Downfall, not the Steam Workshop mod path.
  • The official developer post described the breach window as roughly 12:30-1:30 p.m. Eastern on December 25, 2023.
  • The developer said three users were known to be affected at disclosure time; the durable total may be higher.

Incident Context

Motive
Credential Theft
Cause
Compromised Account Credentials
Transitive
No
User Impact
3

External References

Source record: proprietary/downfall/meta.yaml