Proprietary · · 1 day

Bean Battles Steam update carried trojan

A compromised Bean Battles Steam account reportedly pushed a February 2024 update that installed a trojan and targeted Steam and Discord accounts.

Bean Battles is a small Steam game, and the public evidence is thinner than for Downfall or Traffic. The useful signal is consistent: Steam community and subreddit posts on February 15, 2024 warned that the developer's Steam account had been hacked and that a new update was malware.

The reported payload was described by players as a trojan or Epsilon Stealer. Community reports said the malware triggered when the game was run, hijacked Steam and Discord accounts, and led victims to treat saved browser credentials as exposed.

A later Steam discussion comment quoted the Bean Battles Discord saying the game was safe again on February 16, 2024, after users were told to fully uninstall before reinstalling. This record is included because the attack path matches our scope: the official Steam update channel for a real game appears to have delivered the payload.

The uncertainty stays explicit. This is not modeled with the same confidence as incidents backed by vendor advisories or malware writeups, but it is still useful evidence for the pattern of compromised game distribution accounts turning a normal update into credential-stealing code.

Appendix · Affected releases

app/765410 steam
  • This record relies on community evidence rather than a formal vendor or security report; the compromised Steam update path is the part most directly supported by the available sources.

References

  1. Dev steam account was hacked and game now has a trojan, do not install recent updatereddit.com
  2. Do Not Play, New update is a virussteamcommunity.com
  3. Bean Battles Patch notes - SteamDBsteamdb.info
  4. EpsilonStealer malware samples - MalwareBazaarmalwarebazaar.abuse.ch

Source record: proprietary/bean-battles/meta.yaml