Valve has taken down a game called Piratefi from its Steam digital storefront after security researchers discovered it contained the Vidar information-stealing malware. The malicious software was configured to extract sensitive data including passwords, browser session cookies, and cryptocurrency wallet credentials, posing a direct risk to players' digital assets.
Incident Details
Marius Genheimer, a security analyst with the SECUINFRA Falcon Team, disclosed to TechCrunch that Piratefi was a seemingly normal game but carried a carefully obfuscated Vidar payload. Once installed and launched, the malware operated silently in the background, scanning the system for browser data, cryptocurrency wallet extensions, and stored password files. “This game was very likely a modified version of an existing game template, allowing the attacker to deploy malicious code with minimal effort,” Genheimer noted. Valve acted swiftly upon receiving the security report, removing the game from the Steam store. The company has not disclosed how many players may have downloaded the title before its removal.
Technical Analysis: The Vidar Info-Stealer
Vidar is a widespread information-stealing malware available on darknet markets and has been active in cybercriminal campaigns since 2018. It spreads through phishing emails, cracked software, and disguised games, stealing auto-fill data from browsers, FTP credentials, email client information, and private keys or seed phrases from popular cryptocurrency wallets such as MetaMask, Exodus, and Electrum. Security investigations have linked Vidar to multiple ransomware deployment attempts, where attackers use the stolen data for further social engineering or direct theft of digital assets. The Piratefi incident demonstrates that malicious actors are leveraging low-cost game template replication to cloak Vidar as entertainment content, lowering victims' guard.
Developer Identity Remains a Mystery
The developer listed for Piratefi, Seaworth Interactive, has virtually no online footprint — no official website, social media presence, or past product records. This “ghost developer” phenomenon is common among malicious game distributors, who often use fake identities to register Steamworks accounts and exploit the platform's automated submission pipeline to quickly publish harmful content. Although Valve has review processes for new games, malicious modifications based on legitimate templates can still slip through some checks.
Implications for Cryptocurrency Users
This case serves as a reminder for cryptocurrency users to remain vigilant even when downloading games from major platforms like Steam. Recommended precautions include: avoiding games with very few reviews and unverifiable developers; installing up‑to‑date security software; periodically scanning for unusual processes; and using hardware wallets or dedicated devices for managing large crypto holdings. Steam is also encouraged to strengthen pre‑submission security analysis, particularly for games that require network access or file read/write permissions.
As of press time, Valve has not issued an official statement on the matter but has confirmed that Piratefi has been permanently banned from distribution on Steam. The security community continues to monitor similar threats and urges players to report suspicious games promptly.

