Downfall - A Slay the Spire Fan Expansion

Downfall - A Slay the Spire Fan Expansion

Michael Mayhem  [developer] Dec 26, 2023 @ 2:22pm
Downfall Breach Information (Official)
Hello all, apologies that it took us this long to get an official update out here. The steam accounts themselves were also compromised, so we could only post unofficially.

Yesterday, Table 9 Studio experienced a security breach, at which time an entity replaced our games with malicious software. At the current moment, we know of only 3 users across all of our games that were affected.

The breach window was brief, but every minute is a minute longer than is acceptable. It affected only the main branch of standalone downfall, not the Workshop in any way. The signature that you were impacted would have been a Unity library installer firing off when you tried to launch Downfall (and had recently updated that morning). The time of the breach was roughly 12:30 PM Eastern, probably a little after that considering it takes time for Steam clients to detect an update, lasting until about 1:30 PM. If you were already playing and had seen the game, you're fine, the breach deleted the actual game and replaced it with something else. If you believe this to be affecting you, please contact me on Discord at mikemayhemdevthesecond (a separate account as my main also was compromised as part of the breach). We have some additional information that may help secure you.

We've had reports that the hacked upload was caught by most live protection, including built in Windows Defender, which is good. But, if you did see that Unity library installer, you are unfortunately at risk. If you are, then recommendations at this time are to change important passwords if you are not on 2FA. Sign up for 2FA if you haven't already (that automatically prevents attacks like this from ever working). Run an antivirus scan of your choosing (I use BitDefender, it's free).
Last edited by Michael Mayhem; Jan 15, 2024 @ 5:06pm
< >
Showing 16-17 of 17 comments
Michael Mayhem  [developer] Jan 15, 2024 @ 5:06pm 
Originally posted by Critical Mass:
Was the malware attached to updates for the Downfall mod or to the base game of Slay the Spire?

Only to the Downfall standalone Steam library entry, nothing attached to the base game, and only in that 1 hour window.
Michael Mayhem  [developer] Jan 15, 2024 @ 5:08pm 
Originally posted by xavixavieri:
Hi, I am affected by this and only found out about the problem recently. I had removed the appdata files and disabled the windowsappmanager trojan. I am running malwarebytes now, is there anything else I should do or have a lookout for? Thank you

After much investigation and research I pivoted my team to BitDefender, which was reported to have done a better job of stopping the attack and preventing the trojan from sticking around.
< >
Showing 16-17 of 17 comments
Per page: 1530 50