XERNOX SHIELD Detects New Steam Workshop Malware Missed by 61 VirusTotal Scanners

XERNOX SHIELD successfully detected and terminated newly discovered Steam Workshop malware targeting Hot Lava and Human: Fall Flat. During real-world testing, our free antivirus detected every tested payload, including a malicious script with 0/61 detections on VirusTotal, demonstrating the power of real-time protection and heuristic analysis.

MR. XERNOX

10/11/20262 min read

New Malware Targeting Steam Workshop Users

Recently, cybersecurity researcher and YouTuber Eric Parker reported malicious content associated with Steam Workshop downloads for the popular games Hot Lava and Human: Fall Flat. Following the discovery, XERNOX SECURITY immediately obtained the reported malware samples to evaluate how XERNOX SHIELD would respond to these emerging threats.

The results were remarkable: XERNOX SHIELD detected every tested payload on the first attempt, including a suspicious VBScript that showed zero detections across 61 security vendors on VirusTotal.

Real-World Malware Execution Test

Rather than performing a simple manual scan, our team installed the publicly available free edition of XERNOX SHIELD inside an isolated Windows virtual machine. We then deliberately executed the reported malware samples to observe the software's real-time protection capabilities.

During testing:

  • XERNOX SHIELD successfully detected every tested malware payload.

  • One sample attempted to download and execute an additional payload.

  • The downloaded payload requested administrator privileges through Windows User Account Control (UAC).

  • Our tester deliberately approved the UAC request to evaluate the protection under elevated privileges.

  • XERNOX SHIELD successfully detected and terminated the additional threat, even after administrator access was granted.

These results demonstrate XERNOX SHIELD's ability to respond to malicious activity during actual execution, rather than relying exclusively on manual file scanning.

0/61 Detections on VirusTotal

One particularly interesting sample was a VBScript file named YEId.vbs. At the time of testing, VirusTotal reported that none of its 61 participating security engines flagged the file as malicious. Meanwhile, XERNOX SHIELD classified the same file as malware through its heuristic script analysis.

Detection details:

  • Filename: YEId.vbs

  • SHA-256: 0772a5180d155971b92cad89007da71f8d763346530c82d13e32fab1b70fc948

  • XERNOX SHIELD Verdict: Malware

  • XERNOX SHIELD Detection Score: 100/100

  • VirusTotal Results: 0/61 detections at the time of testing

View the sample on VirusTotal

How Did XERNOX SHIELD Detect It?

XERNOX SHIELD uses a combination of heuristic analysis, suspicious script-pattern recognition, file reputation indicators, and real-time process monitoring to identify potentially malicious activity. Instead of depending entirely on previously identified malware signatures, the detection engine evaluates suspicious characteristics and combinations of behaviors.

In this case, XERNOX SHIELD identified potentially malicious scripting patterns, including Windows Script Host shell execution and ActiveX/COM object creation. These capabilities allow XERNOX SHIELD to identify certain emerging threats even when their file hashes are not associated with known malware signatures.

Protection Available in the Free Edition

Perhaps most importantly, all testing was performed using the free edition of XERNOX SHIELD. No special development build, custom malware signatures, or additional detection rules were introduced for this test. This demonstrates that the same protection capabilities available to everyday users successfully detected and responded to the tested threats.

Our Commitment to Cybersecurity

At XERNOX SECURITY, our mission is to develop accessible, effective cybersecurity software that helps protect users against both known and emerging threats. As an independent cybersecurity company, we believe real-world testing and transparent results are essential to building trust.

This incident provides an encouraging demonstration of XERNOX SHIELD's detection capabilities against recently reported malicious content. We thank cybersecurity researcher Eric Parker for bringing attention to this threat.

Stay protected. Stay ahead of emerging threats.

Contact

Secure your digital world with us.

Email

© 2026. XERNOX SECURITY LLC, All rights reserved.