Downfall Steam build carried Epsilon
A compromised Table 9 Studio account replaced the standalone Steam build of Downfall with Epsilon Stealer on Christmas Day 2023.
Story
Downfall was not a poisoned Steam Workshop mod. It was the standalone Steam package for a major Slay the Spire fan expansion. On December 25, 2023, a breached developer account let the attacker replace the packaged game on the public Steam branch.
The replacement did not behave like Downfall. Players who launched the affected build saw a Unity library installer prompt. That prompt was the visible edge of Epsilon Stealer, which targeted browser credentials, cookies, payment data, Discord and Steam material, Telegram data, and files with password-like names.
The distinction between standalone and Workshop mattered. Players who used the Steam Workshop version of the Slay the Spire mod were not in the same distribution path; the compromised artifact was the standalone app build that Steam delivered as the game package.
Table 9 Studio said the exposure window was brief, roughly 12:30 to 1:30 p.m. Eastern on December 25, and affected the standalone Downfall branch, not the Workshop path. The developer knew of three affected users at disclosure time, but any player who launched during the window was told to scan the system and rotate important credentials.
The incident is included because it shows the same supply-chain shape as larger software compromises at a smaller scale: compromise the publisher account, replace the trusted artifact, and let a normal update or install path put credential-stealing code on user machines.
Affected Artifacts
- Observed
- 2023-12-25
- Compromised Versions
- Unknown
- Fixed
- Not listed
- Evidence
- distribution: store.steampowered.com/app/1865780/Downfall__A_Slay_the_Spire_Fan_Expansion, mirror: steamcommunity.com/app/1865780/discussions/0/4034727291141682949, malware: Epsilon Stealer, observable: Unity library installer prompt appeared when the replaced build was launched. , +2 more
- The official developer post described the affected channel as the main branch of standalone Downfall, not the Steam Workshop mod path.
- The official developer post described the breach window as roughly 12:30-1:30 p.m. Eastern on December 25, 2023.
- The developer said three users were known to be affected at disclosure time; the durable total may be higher.
Incident Context
- Motive
- Credential Theft
- Cause
- Compromised Account Credentials
- Transitive
- No
- User Impact
- 3
External References
- Downfall Breach Information (Official)steamcommunity.com
- Downfall (Steam Standalone) was Breachedsteamcommunity.com
- Steam game mod breached to push password-stealing malwarebleepingcomputer.com
- Downfall was compromised after a security breachreddit.com
- Steam Game Mod Breached to Push Password-Stealing Malwaredailysecurityreview.com
Source record: proprietary/downfall/meta.yaml