Kaspersky's researchers found malware in Wallpaper Engine content.
Dozens of malicious wallpapers disguised hidden programs that hijacked accounts and quietly installed malware on victims' machines. Video-only live wallpaper apps, like SCRYR, avoid the problem entirely: they don't run code in the first place.
What researchers found
On June 16, 2026, Kaspersky's Securelist team published a report on a malware campaign distributed through Wallpaper Engine, the popular app for animated desktops. Attackers uploaded malicious "wallpaper" packages that, once installed, quietly hijacked the victim's Steam account and dropped further malware onto their PC.
According to the research, the campaign involved dozens of malicious packages, several of which had been downloaded thousands to tens of thousands of times each, with activity stretching back to late 2025. Many of the lures were styled as anime and "cute girl" art to attract downloads. Victims were concentrated in China and Russia, with others reported across Singapore, Hong Kong, Germany, Vietnam, India, and Canada.
Meet SCRYR
Turn your desktop into living art
SCRYR is a free live wallpaper app for Mac and Windows that plays a curated library of 4K video on your desktop. Free to start, unlock the full library for $3.95/month. It's safe by design: because it only ever plays video, there's no executable code and no attack surface for malware to exploit. And it's hardware-accelerated for smooth performance that stays light on your machine, runs across multiple monitors, and sets in one click.
How the attack actually works
The campaign abused a specific feature of Wallpaper Engine. Alongside video and image wallpapers, the app supports an "application" wallpaper type: these are not media files at all, they are executable Windows programs that run on your desktop as the background.
That feature exists for legitimate uses like interactive scenes, mini-games, and system monitors, and Wallpaper Engine itself is legitimate software: this was not a flaw in the app, but malicious third-party uploads abusing the feature. But because an application wallpaper is a real program, a malicious one can do anything any program can. In this campaign the payload ran automatically the moment the wallpaper was installed. Some samples shipped the malware bundled directly; others hid it inside password-protected archives with the password embedded, to slip past basic scanning.
Once running, the malware hijacked Steam sessions, then installed additional payloads: a remote-access backdoor, the Lumma and Vidar infostealers, cryptocurrency miners, and in some cases ransomware. Hijacked accounts were then used to help spread the malicious packages further.
The safest fix: a live wallpaper that can't run code
You don't have to give up a live desktop to stay safe. The danger here only existed because a wallpaper was allowed to be a program. It comes down to attack surface: a live wallpaper that is nothing more than a playing video file can't execute code, so this entire category of attack has nothing to grab onto.
So the simplest fix isn't a checklist of precautions you have to remember every time you download something. It's choosing an app that only plays video in the first place. That's exactly what SCRYR does.
Sources
SCRYR and this article are published by Big Visual Chill (LUX LUMN). We are not affiliated with Kaspersky, Valve, Steam, or Wallpaper Engine. Wallpaper Engine and Steam are trademarks of their respective owners, referenced here for reporting and commentary.