
The reported replies turned a real problem into a trap
On July 25, BleepingComputer reported that newly created or otherwise random Steam accounts were replying to forum posts about crashes, lost inventory, and other technical problems. The replies looked helpful but told people to open PowerShell as an administrator and run a command.
According to the publication’s analysis, the command downloaded and installed XMRig mining software. The reviewed sources did not include a public Valve confirmation of this specific campaign, so treat the campaign details as BleepingComputer’s findings, not as an official Steam incident notice.
This follows the broader ClickFix pattern
Switzerland’s National Cyber Security Centre describes ClickFix as social engineering that invents a technical problem or verification step and then persuades the user to paste and execute code. The attacker relies on the user to authorize the action that security controls might otherwise block.
The warning sign is not PowerShell itself. PowerShell is a legitimate Windows tool. The danger is an unknown person asking you to run unexplained code—especially with administrator rights—because a forum post, pop-up, or copied instruction says it is the only fix.
For damaged game files, stay inside Steam
For an ordinary crash or missing-file problem, start with Steam’s documented Verify Integrity of Game Files process. Open the game’s Properties, choose Installed Files, and select Verify integrity of game files. Steam then checks the local files against its own copy.
That path does not promise to solve every crash or inventory issue, but it keeps the first repair attempt inside the client and its official support documentation. If the problem remains, continue through Steam Support or the game publisher’s known support channel rather than a command pasted into a discussion reply.

If you did not run the command, there is no need to panic
Reading the reply, highlighting its text, or closing the page does not execute the command. Do not paste it into PowerShell to test it. Close the instructions, report the suspicious reply through the forum controls, and use an official support route for the original problem.
If you downloaded a file but did not open it, delete it and run a normal security scan if you want an additional check. The response should match what actually happened instead of treating every suspicious post as a confirmed infection.
If you ran it, scan Windows before returning to normal use
Update Microsoft Defender so it has current protection information, then run a full scan and remove or quarantine anything it detects. Microsoft says recurring detections can indicate a hidden component reinstalling the malware; in that case, save your work and use Microsoft Defender Offline.
Do not rely only on whether the PC feels slow or whether a miner process is visible. If Defender cannot complete a scan, detections return, or the computer continues behaving unexpectedly, stop sensitive activity on that PC and get qualified help rather than improvising manual deletions from another forum post.

Then review Steam and the email account behind it
After the malware check, review Steam’s authorized devices and active sessions. Sign out devices or sessions you do not recognize. Change the Steam password and the password for the connected email account, especially if either password was entered while the suspicious command was running or reused elsewhere.
Confirm that Steam Guard is enabled and that its recovery details still belong to you. Make these changes from a device you trust. Account checks do not replace the Windows scan, and a clean scan does not replace reviewing sessions if a credential or session may have been exposed.
One last check
Five checks before you follow a forum fix
- 01
Stop if a reply asks you to open PowerShell or another command line as administrator.
- 02
Use Steam’s built-in Verify Integrity of Game Files path for an ordinary game-file problem.
- 03
If you did not run the command, close the instructions and report the reply without assuming the PC is infected.
- 04
If you ran it, update Microsoft Defender, run a full scan, and use an offline scan if the threat keeps returning.
- 05
Review Steam devices and sessions, then secure Steam, email, and Steam Guard from a trusted device.
Sources
Sources used for this article
- BleepingComputer — Steam forum ClickFix attacks install XMRig
- Swiss NCSC — How ClickFix installs malware
- Steam Support — Verify Integrity of Game Files
- Steam Support — Account Security Recommendations
- Microsoft Support — Detecting and removing malware
Sources checked on July 27, 2026. The Steam campaign details come from BleepingComputer’s July 25 report; Valve had not publicly confirmed this specific campaign in the reviewed sources. The response steps use general ClickFix guidance from the Swiss NCSC and official Steam and Microsoft support paths.
Was this guide useful?
This browser can leave one heart per article.
