A new malware campaign has targeted users of the indie game platform Itch.io and Patreon by distributing the Lumma Stealer malware through fake game update links. Attackers created new accounts to spam comment sections of legitimate games on Itch.io, posting templated messages that claimed to offer game updates. These messages included links to archives such as “Updated Version.zip,” which, when downloaded, contained a malicious executable designed to deploy Lumma Stealer. The campaign also leveraged a reflective Node.js loader to evade detection and increase the likelihood of successful infection.
Security researchers observed that the attackers used a shotgun approach, spamming multiple games to maximize reach and exploit users unfamiliar with the platform. The malicious files were often hidden among benign files in the downloaded archive, making it harder for users to detect the threat. This campaign highlights the growing trend of threat actors targeting indie gaming communities and platforms beyond mainstream services like Steam, using social engineering and technical obfuscation to distribute credential-stealing malware.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting described the same campaign as targeting Itch.io users through fake updates and a reflective Node.js loader to deploy Lumma Stealer. This reinforced the public understanding of the social-engineering and malware-delivery methods used in the operation.
Analysis revealed that the downloaded archive contained a nexe-packed Windows executable posing as a game file, which unpacked an obfuscated JavaScript loader with anti-analysis and anti-VM checks. If those checks passed, the loader dropped a Base64-encoded native module to %temp% and used it to reflectively load and execute a Lumma Stealer payload.
An ongoing malware campaign abused Itch.io game comment sections with fake "game update" messages that directed users to Patreon-hosted archives such as "Updated Version.zip." The operator reportedly continued creating new Itch.io accounts after bans to sustain the distribution effort.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.