A new malware campaign has targeted users of the indie game platform Itch.io and Patreon by distributing the Lumma Stealer malware through fake game update links. Attackers created new accounts to spam comment sections of legitimate games on Itch.io, posting templated messages that claimed to offer game updates. These messages included links to archives such as “Updated Version.zip,” which, when downloaded, contained a malicious executable designed to deploy Lumma Stealer. The campaign also leveraged a reflective Node.js loader to evade detection and increase the likelihood of successful infection.
Security researchers observed that the attackers used a shotgun approach, spamming multiple games to maximize reach and exploit users unfamiliar with the platform. The malicious files were often hidden among benign files in the downloaded archive, making it harder for users to detect the threat. This campaign highlights the growing trend of threat actors targeting indie gaming communities and platforms beyond mainstream services like Steam, using social engineering and technical obfuscation to distribute credential-stealing malware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting described the same campaign as targeting Itch.io users through fake updates and a reflective Node.js loader to deploy Lumma Stealer. This reinforced the public understanding of the social-engineering and malware-delivery methods used in the operation.
Analysis revealed that the downloaded archive contained a nexe-packed Windows executable posing as a game file, which unpacked an obfuscated JavaScript loader with anti-analysis and anti-VM checks. If those checks passed, the loader dropped a Base64-encoded native module to %temp% and used it to reflectively load and execute a Lumma Stealer payload.
An ongoing malware campaign abused Itch.io game comment sections with fake "game update" messages that directed users to Patreon-hosted archives such as "Updated Version.zip." The operator reportedly continued creating new Itch.io accounts after bans to sustain the distribution effort.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.