Did a Programming Game Just Open the Door to Your PC? The Screeps: World Exploit Unpacked.

AI Gaming News Author · kotaku ·

Did a Programming Game Just Open the Door to Your PC? The Screeps: World Exploit Unpacked.

A popular programming game on Steam, Screeps: World, found itself in hot water over a reported remote code execution vulnerability that devs initially downplayed but then patched, while allegations surface that Valve ignored warnings – leaving us all wondering about digital safety and platform responsibility, eh?

Right, so imagine you’ve just conjured a magnificent spell, all intricate incantations and shimmering energy, only for it to backfire spectacularly, opening a portal directly into... well, your mate's gaming rig. That's kinda the vibe I'm getting from this whole Screeps: World kerfuffle, a story that’s wilder than finding an ancient artifact in your breakfast cereal.

Screeps: World, for the uninitiated, isn’t your average point-and-click adventure or button-mashing brawl. It’s an open-source MMO RTS sandbox game where players literally write JavaScript code to craft their AI units, managing resources and battling other player-coded factions. Sounds pretty neat, doesn’t it? A game for true programming enthusiasts, where your brain is the most powerful GPU. It's currently sitting pretty with a "Very Positive" rating on Steam, and over 113,000 purchases according to VG Insights – a solid community by any measure.

Now, here’s where things get interesting, and a touch alarming. An 'information security aficionado' – sounds like a title straight out of a cyberpunk novel, doesn't it? – by the name of Isaac King popped up on X (the platform formerly known as Twitter, bless its chaotic heart) with some rather damning claims. He alleged that Screeps: World basically allowed 'any other player in the game world to gain remote access to your computer' through a programming exploit. Remote Code Execution, or RCE, for short. Sounds about as friendly as a rogue fireball to the face, eh?

King’s initial post, and a highly detailed write-up on his blog (which I’d recommend a peek at if your brain enjoys a good JavaScript puzzle), laid out the specifics of how this RCE vulnerability apparently worked. Essentially, by crafting malicious code within the game’s programming environment, one player could potentially gain control of another’s machine. Given the game’s very nature, this is like finding out your magic spellbook actually contains a recipe for destroying your own tower.

To put it in terms even us non-coders can grasp, King offered a cracker of an analogy: 'imagine if there were one particular kind of unit in Starcraft that, if you trained it, let people hack your computer. And when pointed out, the game designers said ‘well this is self-inflicted, the players all chose to train that unit’.' Bloody hell, that's a wild premise for an argument, isn't it? It suggests a rather... unique interpretation of user responsibility.

Now, you’d think a claim like 'your game lets people hack other people's PCs' would get an immediate, frantic response. And eventually, it did. But not before a bit of a dance. King’s blog post reckons the developers, Screeps, LLC, were aware of this issue since at least July 2024. A dev reportedly replied to a GitHub report back then, stating they 'do not see this as a serious security threat.' Which, I don’t know, sounds a bit like saying 'this dragon isn't a serious threat, it only breathes fire *sometimes*.' A user on the Screeps Discord even chimed in, noting the vulnerability had been successfully abused in the past. Yikes.

Fast forward to King's public post, kicking up a digital dust storm. The official Screeps X account fired back, calling the accusation 'at the very least, a clickbait exaggeration, and at worst, malicious defamation intended to cause reputational damage.' Strong words, mate. But here's the kicker: they *also* confirmed that 'as of January 25,' the alleged vulnerability had been *removed* from the game. So, it was clickbait exaggeration, but also real enough to patch? My wizard senses are tingling with a whiff of corporate spin there. If it wasn't a problem, why was it fixed, eh?

This is where the plot thickens and my gently skeptical antennae start twitching wildly. King’s blog post made another rather worrying claim: he reported the issue directly to Steam, and 'of course they ignored' him. He then mused, rather cynically but perhaps not unfairly, that Valve’s terms of service make them 'not liable for any hacks caused by malware on the platform.' Meaning, if they're still getting their cut from sales, why rock the boat? Now, Lewis Parker, writing for Kotaku, reached out to Valve for comment, and we’re all waiting to see if they break their usual silence on these sorts of matters.

If that’s true, if a serious RCE vulnerability was reported to Valve and seemingly ignored, well, that's a pretty chunky dragon to ignore, isn't it? It begs the question: what's the responsibility of a platform that hosts hundreds of thousands of games, some of which interact with player systems in complex ways? Is 'not liable' truly good enough when user safety is on the line? It’s a bit like a landlord saying 'not my problem if your flat's got a hole in the roof, you chose to live here.' Not exactly comforting for players putting their trust (and their PC's security) in these digital storefronts.

This whole saga, reported originally by the ever-vigilant Lewis Parker over at Kotaku, isn't just about one programming game and a bit of code gone sideways. It’s a fascinating, if slightly terrifying, glimpse into the intricate dance between game developers, security researchers, and massive platforms like Steam.

For Screeps: World players, it's a stark reminder that even in a game about coding, the code can bite back in unexpected ways. It forces us to ask: how much responsibility do we place on players in a 'programming game' to understand every potential exploit? Is 'self-inflicted' really a defence when the tools provided by the game enable such a severe vulnerability? I reckon that's a tough pill to swallow for anyone who just wanted to build some cool AI without having their PC hijacked.

And for Valve, if King's claims hold water, it’s a moment to perhaps reassess their role. While I’m always cautiously optimistic about the gaming ecosystem, stories like this highlight the pressure points where player trust can erode quicker than a poorly rendered texture in an early access title. We want our digital playgrounds to be safe, mate, not potential vectors for unwanted visitors.

It’s a bit of a wild ride, this one. A game built on code, nearly undone by code, with a platform seemingly shrugging its digital shoulders. It’s certainly got me wondering what other digital traps might be lurking in the gaming multiverse. Always be curious, always be cautious, and maybe don't train that StarCraft unit that hacks your PC, eh?

Tags: Gaming Security, Exploits, Steam, Indie Games, Valve

Original article: kotaku