The popular 2D platformer-shooter BlockBlasters has been pulled from Steam after researchers uncovered that its late-August patch contained malicious components capable of stealing sensitive information from players.
The title, developed by Genesis Interactive, gained strong initial reviews following its July release. However, the update deployed on August 30 (Build 19799326) introduced malware that placed hundreds of users at risk.
Security firm G DATA flagged the discovery, confirming that the patch delivered a multi-stage info-stealing operation rather than simple bug fixes.
Trojan Batch Scripts and Stealer Malware
According to the analysis, the malicious sequence begins with a file named game2.bat. This script abuses Windows commands to collect data such as IP location, Steam login credentials (SteamID, AccountName, PersonaName, RememberPassword), and details of installed antivirus products.
The data is then uploaded to a command-and-control (C2) server at 203[.]188[.]171[.]156:30815/upload. In an evasion tactic, the malware checks whether only Windows Defender is active; if so, it unpacks password-protected archives containing further payloads.

The batch file proceeds to execute two Visual Basic scripts, launch1.vbs and test.vbs, which in turn run additional payload batches.
These scripts collect browser extensions and extract data from locally installed cryptocurrency wallets, which are increasingly common targets for infostealer campaigns. Evidence shows that harvested information is exfiltrated back to the same C2 server.
The infection escalates further when 1.bat modifies Microsoft Defender settings to exclude the game’s binary subdirectory from scans, ensuring that the malicious executables can operate without interruption.
Once exclusions are set, the malware launches additional payloads while simultaneously executing the actual game process to mask its activity.
The key binaries deployed include Client-built2.exe and Block1.exe. The first acts as a backdoor, written in compiled Python, enabling remote operators to maintain persistent access.
The second is a variant of the StealC malware family, written in C++, which harvests user data from browsers, including Google Chrome, Microsoft Edge, and Brave.
Notably, StealC employs outdated RC4 encryption to obfuscate its strings and connects to a secondary C2 server at 45[.]83[.]28[.]99 for data exfiltration.
Steam Removes Game Amid Player Backlash
Telemetry from SteamDB and Gamalytic indicates that more than 100 players downloaded the patched build, with 1–4 players engaging actively at any given time in early September.
Reports also confirmed that at least one streamer became infected during a charity livestream, highlighting the real-world consequences of such attacks.

BlockBlasters has since been flagged as “suspicious” and removed from Steam. The case follows a troubling rise in malicious games on the platform, echoing previous infections from titles like PirateFi and Chemia.
Security experts emphasize that this trend demonstrates how threat actors are exploiting the trust gamers place in digital distribution platforms.
Players are urged to remove BlockBlasters from their systems immediately, perform thorough antivirus scans, and monitor their crypto wallets and accounts for suspicious activity.
Indicators of Compromise
[1] Game2.bat
aa1a1328e0d0042d071bca13ff9a13116d8f3cf77e6e9769293e2b144c9b73b3
BAT.Trojan-Stealer.StimBlaster.F
[2] Launch1.vbs
c3404f768f436924e954e48d35c27a9d44c02b7a346096929a1b26a1693b20b3
Script.Malware.BatchRunner.A@ioc
[3] Test.vbs
b2f84d595e8abf3b7aa744c737cacc2cc34c9afd6e7167e55369161bc5372a9b
Script.Malware.BatchRunner.A@ioc
[4] 1.bat
e4cae16e643a03eec4e68f7d727224e0bbf5415ebb0a831eb72cb7ff31027605
BAT.Trojan-Stealer.StimBlaster.I@ioc
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates