In an alarming incident that has stirred the gaming community, the beloved mod for the card game Slay The Spire, known as Downfall, was compromised to spread dangerous malware. This breach, which occurred on Christmas Day, led to malicious software being distributed through the gaming platform Steam, according to the developers of the mod. The intent of the malware was nefarious: it was programmed to steal passwords from users’ internet browsers and from widely-used messaging services such as Telegram and Discord.
The users affected by this attack would have encountered a suspicious "Unity library installer popup" when they initiated Downfall. This was a clear sign that the mod had been hijacked. Nevertheless, the developers were quick to respond, and by around 1:40pm Eastern Time on December 25th, they had managed to reverse the hack, as stated in their announcement to the gaming community.
Despite the rapid response, the fallout from the malware was a concern. Notably, the developers highlighted that most antivirus software did not prevent the malware itself from executing on a system. However, these security programs did manage to intervene before its payload — the harvested data — could be transmitted over the internet. This meant that, while the initial attack could not be stopped, the actual damage, which would occur when the stolen information was sent out, could be prevented.
The specifics of the data targeted by this malware were quite alarming. The developers pointed out that the malicious program aimed to scrape passwords directly from users' browsers, affecting a range of web browsers including Google Chrome, Microsoft Edge, Mozilla Firefox, and others like Brave and Vivaldi. The malware also targeted login credentials for Windows and passwords for Telegram and Discord. Moreover, it sought out any files potentially containing sensitive information by scanning for the word 'password' in the filenames.
Reports from users indicated that the malware created files in various locations within their hard drives; the announcement by the developers included some examples of these file locations. To mitigate the risk of further breaches, the developers advised users to thoroughly investigate any suspicious files, but to do so while disconnected from the internet. This would help prevent any further data from being compromised.
An additional step recommended by the developers for those who encountered the Unity library installer popup was to change crucial passwords. This was especially urged for passwords that did not have two-factor authentication (2FA) enabled, as these would be more vulnerable to unauthorized access.
Downfall is not just any mod; it has been a huge hit within the Slay The Spire community. It brings a wealth of new content to the game, incorporating new modes and playable characters, enriching the game experience for the players. The breach not only disrupted the fun and excitement around this mod but also raised serious concerns about online security and the safety of user information.
Following the setback with Downfall, the mod's developers have shifted their creative energies towards a new project: Tales & Tactics. This standalone game takes the form of an auto-battling Chess roguelike, building on the innovation and gameplay styles the developers are known for.
At the core of this incident is a stark reminder for users about the importance of digital vigilance. Gamers are encouraged to stay alert for any unusual activity when playing online, to maintain robust antivirus protection, and to ensure that all passwords are secure — ideally with two-factor authentication where possible. It is a call to action for the gaming community and developers to work collaboratively towards a secure gaming environment where entertainment does not come at the expense of personal security.
