Project Zomboid’s malware scare just exposed a bigger problem with Steam mods

Project Zomboid’s malware scare just exposed a bigger problem with Steam mods

ethan Smith·4/10/2026·11 min read

Steam’s Workshop has always run on a quiet assumption: that “Subscribe” is basically safe. The Project Zomboid incident blows a hole in that idea, and not just for one survival game or one bad actor, but for how we treat mods in 2026.

  • 14 Steam Workshop mods for Project Zomboid’s unstable Build 42 were pulled after devs found heavily obfuscated code creating malicious files outside the game folder.
  • All the mods came from a single uploader, now banned, and were disguised as unofficial add-ons to a popular soundtrack mod.
  • Only Build 42 was vulnerable; players on the stable Build 41 are not believed to have been exposed to the exploit path.
  • Unsubscribing is not enough: affected users are being urged to treat this as a real malware incident and scan their systems.

One rogue modder, 14 banned mods, and a hole in Build 42

The Indie Stone, the studio behind Project Zomboid, has removed 14 Steam Workshop entries and banned their uploader after discovering what it bluntly calls “malicious code.” This wasn’t a vague “maybe” situation: in the studio’s own description, the Lua scripts inside those mods were heavily obfuscated and were actually writing files outside Zomboid’s own directory.

The affected uploads all posed as unofficial extensions for the True MoooZIC soundtrack mod – basically audio add-ons for a well-liked piece of community content. That is exactly the kind of low-stakes, harmless-sounding mod most players subscribe to without a second thought.

Based on subscriber counts, The Indie Stone estimates somewhere between roughly 500 and 2,200 devices installed at least one of the malicious mods before the takedown. That’s not a planet-wide catastrophe, but it is a non-trivial number of PCs that now need to be treated as potentially compromised.

Crucially, this was not a random Steam-wide vulnerability. The exploit specifically targeted Project Zomboid’s experimental Build 42 branch. The devs say Build 41, the current stable version, is both unaffected and not vulnerable to the same trick. If you never opted into Build 42, you’re outside the blast radius of the actual exploit.

But if you did run Build 42 and subscribed to any of those 14 mods, this stops being a “game bug” and becomes a straight PC security issue. And that’s where this story stops being about one survival sim and starts being about how game modding is handled more broadly.

How a harmless-sou