Valve has swiftly removed a game titled Piratefi from its Steam store after security researchers discovered that the game was deliberately infected with malware designed to steal cryptocurrency wallets and other sensitive information.
Vidar Malware: A Targeted Information Stealer
Analysis by Marius Genheimer of the SECUINFRA Falcon Team, shared with TechCrunch, revealed that Piratefi contained the Vidar info-stealer. Vidar is capable of extracting saved passwords, browser session cookies, and — most critically — cryptocurrency wallet credentials, including private keys and seed phrases. Once harvested, this data can be used by attackers to drain victims' digital assets remotely.
Genheimer noted that Piratefi appeared to be a modified version of an existing game template, requiring minimal effort from the attackers to deploy the malicious payload. This technique, sometimes called "gamified phishing," exploits the trust of players seeking indie titles on platforms like Steam.
Mysterious Developer: Seaworth Interactive
The game was listed under the developer name Seaworth Interactive, but investigators could find no verifiable online presence — no official website, social media accounts, or development history. The security community suspects the name is a front created specifically to distribute malware.
Vidar has previously been linked to various cybercriminal operations, including attempts to deploy ransomware. This incident underscores the growing threat of malware disguised as legitimate games, and highlights the challenge platforms face in vetting every upload.
What Steam Users Should Do
While Valve's review process catches many threats, sophisticated malware can still slip through. Users who downloaded Piratefi are advised to uninstall it immediately and run a full antivirus scan. It is also wise to avoid entering cryptocurrency wallet information on any device used for gaming, and to enable multi-factor authentication on exchange accounts.
As of now, Steam has removed all traces of Piratefi from its storefront. The incident serves as a reminder for the crypto community to remain vigilant against social engineering and software-based attacks.

