Project Zomboid Bans Malicious Steam Workshop Mods

By Central

The indie game community was recently confronted with a significant security threat involving its own content. The developers of Project Zomboid, The Indie Stone, have taken decisive action by removing a series of malicious modifications from the Steam Workshop and banning their creator. This article details the nature of the security breach, the studio’s response, the specific mods affected, and the critical security steps players must take.

The Discovery of Malicious Mods

Following user reports, The Indie Stone launched an immediate investigation into suspicious Project Zomboid mods on the Steam Workshop. The team confirmed the presence of heavily obfuscated, malicious code within these add-ons. The investigation revealed that the mods were capable of creating files outside the standard game installation directory, a clear indicator of a security risk. The studio moved swiftly to delist 14 mods created by a single author, which had been installed on an estimated 50 to 2,200 user devices.

Developer Statement and Urgent Security Warning

In an official Steam blog post, The Indie Stone issued a stark warning to the community. “At this time, the full scope and behavior of the malicious files have not been fully determined,” the statement explained. “However, because these mods were capable of creating files outside the game directory, we strongly recommend that anyone who downloaded them take appropriate security measures to ensure their system is safe. Simply uninstalling the mods is not sufficient.” This advisory underscores that users who installed these mods must conduct a thorough system security check using reputable antivirus or anti-malware software.

Technical Details and Build Vulnerabilities

Further analysis revealed the malicious code was specifically triggered when Project Zomboid was run using the Build 42 update branch. In response, The Indie Stone has updated the “outdatedunstable” branch to match the current “unstable” branch, effectively closing this known vulnerability. To prevent future exploitation, the developers announced that the “outdatedunstable” branch will now intentionally lag one content update behind the main “unstable” branch going forward. Additionally, separate security updates were released for Build 41 to address a different vulnerability identified during an internal audit; there is currently no evidence this second flaw was exploited.

List of Delisted Malicious Mods

All the removed mods were presented as add-ons for the popular “True Moozic” framework but were unaffiliated with the original True Moozic author. Below is the complete list of malicious mods, as provided by The Indie Stone, including their Steam Workshop IDs and internal Mod IDs.

  • Risk of Rain 2 OST (True MoooZIC) Workshop ID: 3681934105 – Mod ID: RiskOfRain2Music
  • Risk of Rain 1 OST (True MoooZIC) Workshop ID: 3681810963 – Mod ID: RiskOfRain1Music
  • NieR: Automata OST (True MoooZIC) Workshop ID: 3681765529 – Mod ID: NierAutomataMusic
  • -Katana ZERO OST (True MoooZIC) Workshop ID: 3681764942 – Mod ID: KatanaZeroMusic
  • Persona 5 OST (True MoooZIC) Workshop ID: 3681756112 – Mod ID: Persona5Music
  • Jujutsu Kaisen S1 OST (True MoooZIC) Workshop ID: 3681755051 – Mod ID: JujutsuKaisenMusic
  • Hotline Miami 2: Wrong Number OST (True MoooZIC) Workshop ID: 3681719339 – Mod ID: HotlineMiami2Music
  • Hotline Miami OST (True MoooZIC) Workshop ID: 3681718339 – Mod ID: HotlineMiami1Music
  • Silent Hill OST (True MoooZIC) Workshop ID: 3681477980 – Mod ID: SilentHillMusic
  • Cowboy Bebop OST (True MoooZIC) Workshop ID: 3681476976 – Mod ID: CowboyBebopMusic
  • Metal Gear Rising: Revengeance Vocal Tracks (True MoooZIC) Workshop ID: 3681339955 – Mod ID: MGRRevengeanceMusic
  • Classic Roblox Music (True MoooZIC) Workshop ID: 3681335952 – Mod ID: RobloxClassicMusic
  • DELTARUNE Ch3+4 Music (True MoooZIC) Workshop ID: 3681334251 – Mod ID: DeltaruneCh34Music
  • Minecraft Alpha+Beta OST (True MoooZIC) Workshop ID: 3680972796 – Mod ID: MinecraftClassicMusic

Implications for Modding Communities

This incident serves as a critical reminder of the inherent risks within open modding ecosystems like the Steam Workshop. While community-created content is a pillar of games like Project Zomboid, it also presents a vector for bad actors to distribute malware under the guise of legitimate add-ons. The fact that these mods successfully impersonated a trusted framework (True Moozic) highlights a sophisticated social engineering tactic designed to bypass user caution. It underscores the necessity for players to exercise heightened vigilance, scrutinize mod sources, and maintain robust system security even when downloading from official storefronts.

The prompt and transparent response from The Indie Stone establishes a responsible precedent for developer intervention in such security crises. By publicly naming the offending mods, detailing the technical vulnerabilities, and immediately implementing structural changes to their distribution branches, the team has prioritized player safety. This event reinforces the ongoing challenge of securing player-created content platforms and establishes a clear expectation for other studios to maintain proactive oversight and rapid response protocols to protect their communities from similar threats.

Share This Article