The Short Version
The evidence shows that attackers did use Steam Workshop items for Wallpaper Engine to distribute malware. Security researchers documented malicious “application wallpapers” carrying credential-stealing and remote-access payloads, and Wallpaper Engine’s developers later confirmed the abuse and tightened restrictions. The important caveat is that this was not every wallpaper type, but a specific executable-capable category.