Basically what happens is that there are bots that are chatting on Twitch that promises users the chance to win items for Counter-Strike: Global Offensive. However when these users click the link that they are given, they instead find themselves with an empty Steam wallet. The malware has been dubbed “Eskimo” and not only can it steal your Steam account, but it is also able to take screenshots, add new Steam friends, and trade items.
According to F-Secure, “All this is done from the victim’s machine, since Steam has security checks in place for logging in or trading from a new machine.” The company then suggests that perhaps Valve could implement an additional layer of security to prevent items from being traded to newly-added friends.
“It might be helpful for the users if Steam were to add another security check for those trading several items to a newly added friend and for selling items in the market with a low price based on a certain threshold. This will lessen the damages done by this kind of threat.” Twitch claims that they have since blocked the link in question, but if you have clicked on suspicious links recently, perhaps it’s best to run a system scan.