It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
Scammers are actively using a ( http://en.wikipedia.org/wiki/Cross-site_scripting ) cross-site scripting exploit on Steam profiles to commit fraud.

Some things which can happen with cross-site scripting:

- Fraudulent store/market purchases

- Trading your items away to a scammer (if you aren't paying attention to mobile auth)

- Sending tradeable/giftable games away (mobile confirmation NOT required)

- Redirecting to phishing website within Steam client itself, potentially hijacking account

- Downloading malware (ransomware, Steam stealers, key loggers, etc)

- Other nasty things I will not elaborate on

Do not view any Steam profile links while logged in, even legitimate, until further notice. It doesn't matter whether you do this within Steam itself, the in-game overlay, or any web browser such as Edge/Firefox/Chrome. If affected, you won't see any of this happening until it's too late.

Keep an eye on your market/store transaction history and gift history for unrecognized purchases, and do not approve any unrecognized or suspicious trades or market listings from the Steam mobile authenticator. Do not assume any Steam profiles are safe to look at.

For more information: https://www.reddit.com/r/Steam/comments/5skfg4/warning_regarding_a_steam_profile_related_exploit/
Source:
Traders Guild
http://steamcommunity.com/gid/103582791432720446#announcements/detail/675940099452325094
Oh that's bad. I recall reading about something similar about a year or so ago with people seing others profiles instead of their own and in different languages.
Let's hope they sort it out quickly and not many people get affected.
Post edited February 07, 2017 by Siegor
So... I take it there's a way to add scripts to your profile using one of the showcases?

edit: Yup, looks like it was the "Guide" showcases that were being exploited. Valve has disabled them so that profiles can't get booby-trapped from now on, but some existing profiles might still be trapped from before.
Post edited February 07, 2017 by Barefoot_Monkey
Thanks for the warning.
How come this isn't getting any attention anywhere? Is this legit?
avatar
KneeTheCap: How come this isn't getting any attention anywhere? Is this legit?
As legit as 45th :D

The issue supposedly fixed.
Valve is indeed. A walking security risk.
avatar
KneeTheCap: How come this isn't getting any attention anywhere? Is this legit?
avatar
BlackDawn: As legit as 45th :D
Excuse me, but what does the "as 45th" mean? I've never heard this idiom.
avatar
Nightblair: Excuse me, but what does the "as 45th" mean? I've never heard this idiom.
Hazarding a guess that it's like saying, "as legit as Trump being elected the 45th US president."
Thanks for the warning, I haven't used Steam in a month, but I'm hopefully not affected.
avatar
JK41R4: Thanks for the warning, I haven't used Steam in a month, but I'm hopefully not affected.
If I'm not mistaken you are only at risk if you click on someone's profile which has been compromised.
avatar
Siegor: If I'm not mistaken you are only at risk if you click on someone's profile which has been compromised.
Ah, I see, thanks. So don't go anywhere while logged in, don't go to anyone's profile.
Well, Galaxy client is not available for Linux. I bet, I am secure.
avatar
JK41R4: Ah, I see, thanks. So don't go anywhere while logged in, don't go to anyone's profile.
Update:
https://www.reddit.com/r/Steam/comments/5smjle/an_xss_exploit_on_steam_profiles_has_been_fixed/