Researchers found that Dota 2 shipped an outdated, unsandboxed build of Google’s V8 JavaScript engine, allowing attackers to achieve remote code execution through malicious JavaScript embedded in custom game modes. One Steam-published custom mode directly exploited CVE-2021-38003, a V8 flaw tied to a Chromium issue involving JSON.stringify, while three other malicious modes used a quieter backdoor that fetched and executed attacker-controlled JavaScript from a command-and-control server.
The malicious game modes were all published by the same author and targeted players who joined those custom matches, turning the game’s Panorama client-side JavaScript into a path across a security boundary and onto players’ systems. After disclosure, Valve upgraded V8, removed the malicious game modes from Steam, notified affected users, and added mitigations; the company said fewer than 200 players were impacted.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers inferred that a custom game mode later identified as malicious likely began as a legitimate mode and had malicious functionality added in March 2022. The modified mode embedded a JavaScript exploit for CVE-2021-38003 and included suspicious server-side Lua code.
A Chromium security bug describing a V8 issue involving JSON.stringify leaking TheHole value, leading to remote code execution, was published. This bug corresponds to CVE-2021-38003 later referenced in the Dota 2 exploitation chain.
On January 12, Valve upgraded Dota 2's V8 engine, removed the malicious custom game modes, notified affected players, and added mitigations. Valve said fewer than 200 players were affected.
Researchers discovered four Steam-published Dota 2 custom game modes by the same author that abused Dota 2's outdated, unsandboxed V8 engine. One directly embedded a CVE-2021-38003 exploit, while three others used a backdoor to fetch and execute arbitrary JavaScript from a command-and-control server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.