
Steam’s Workshop has always run on a quiet assumption: that “Subscribe” is basically safe. The Project Zomboid incident blows a hole in that idea, and not just for one survival game or one bad actor, but for how we treat mods in 2026.
The Indie Stone, the studio behind Project Zomboid, has removed 14 Steam Workshop entries and banned their uploader after discovering what it bluntly calls “malicious code.” This wasn’t a vague “maybe” situation: in the studio’s own description, the Lua scripts inside those mods were heavily obfuscated and were actually writing files outside Zomboid’s own directory.
The affected uploads all posed as unofficial extensions for the True MoooZIC soundtrack mod – basically audio add-ons for a well-liked piece of community content. That is exactly the kind of low-stakes, harmless-sounding mod most players subscribe to without a second thought.
Based on subscriber counts, The Indie Stone estimates somewhere between roughly 500 and 2,200 devices installed at least one of the malicious mods before the takedown. That’s not a planet-wide catastrophe, but it is a non-trivial number of PCs that now need to be treated as potentially compromised.
Crucially, this was not a random Steam-wide vulnerability. The exploit specifically targeted Project Zomboid’s experimental Build 42 branch. The devs say Build 41, the current stable version, is both unaffected and not vulnerable to the same trick. If you never opted into Build 42, you’re outside the blast radius of the actual exploit.
But if you did run Build 42 and subscribed to any of those 14 mods, this stops being a “game bug” and becomes a straight PC security issue. And that’s where this story stops being about one survival sim and starts being about how game modding is handled more broadly.