Trending: Silksong patch 4Search
iHeartGeek
iGaming

People Playground shuts Workshop after malware returns

The developer behind People Playground has shut the game's Steam Workshop again after a malicious mod wiped player data and vandalised Steam cloud saves, warning players not to launch it until it is declared safe.

A white ragdoll figure seated on the turret of a green tank on a grey grid background, in a scene from *People Playground*.

The developer of People Playground has disabled the game's Steam Workshop after another malicious mod spread through it, and has told players to check their machines. The community announcement, titled “Bad event”, went up on 22 September 2026 and points at a window on the evening of 21 September, between 18:00 and 20:00 CEST. Anyone who had mods installed and opened the game in that window is advised to run an anti-virus scan, delete their mods folder and keep People Playground closed until the developer says otherwise.

What the developer says the mod did

Writing on Steam, mestiez is careful to say that the exact behaviour is not known. “I can’t say with certainty what exactly happened or what this program did, but it’s not looking good,” the post reads. By that account the mod permanently wipes a considerable amount of personal data, vandalises Steam configuration and Steam cloud data, including inventory and workshop data for other games, reads the player’s Discord username and other identifiable information and publishes it to the Workshop, and copies itself into the Workshop in order to spread. Credentials are not part of it. “It will not hack you, but it’s a catastrophic piece of malware nonetheless,” the developer writes.

The advice that follows is blunt: change the Discord password straight away, and change the passwords on other important accounts too, so that any session tokens caught up in the incident stop working.

A second outbreak in the same year

This is not the first time People Playground has been hit. The Workshop was shut in February 2026 over a similar malicious addon and reopened on 6 February after the developer reworked how mods are handled, including a rule that mods no longer update themselves and have to be approved again whenever their contents change. In the note that reopened the Workshop, mestiez wrote that they had to pay closer attention, that more moderators were needed and that this was not something one person could carry, adding: “I should’ve listened.”

People Playground has been on Steam since July 2019 and is published by Studio Minus. It is a sandbox built around ragdolls and physics, and the Workshop is central to how it is played, which is what makes an attack on mods so costly for the people who own it.

Why a mod channel is the weak point

Steam Workshop items run inside the game on the player’s own machine, so a malicious upload arrives with the same trust a player extends to the game itself. The developer says nobody knows who was responsible and asks players not to turn on anyone: “Do not harass anyone or blame anyone other than me,” the post reads. “This is entirely my responsibility.”

Our opinion

The lesson People Playground keeps teaching is that the Workshop is not an add-on to the storefront, it is the attack surface. A sandbox whose whole appeal lives in community-made content cannot switch that channel off without gutting the thing people bought, and February’s fix, making mods prove their contents before an update lands, was the right shape and clearly not enough. One developer cannot moderate a Workshop by eye, which is exactly what February’s note concedes when it admits that one person cannot do it alone.

What should bother Valve more than it appears to is where the cost lands. The platform runs the upload path, hosts the files and lends the badge of legitimacy that makes a Workshop item look safe, yet the compromise is discovered by the developer and the remedy, changing passwords, falls on players. A mod that rewrites files well outside its own folder or publishes a Discord handle to the Workshop should not be something its victims learn about from a community post.

None of that moves the blame. The developer is right that the uploader did this, and right to say so plainly instead of hiding behind a patch note; it takes nerve to write “do not blame anyone other than me” about an attack you did not carry out. But a small studio running a Workshop at this scale is a supply-chain risk that keeps being treated as a personal failing, and until the checking happens at the platform rather than at the developer, expect the same announcement again, here or somewhere very like it.