Valve has announced additional security measures for developers publishing games on Steam, including SMS-based verification codes, in response to the recent emergence of malicious updates that push malware from affected publisher accounts.
See also: Steam: Malware is spreading through the store

Steamworks is a set of tools and services that game/software developers and publishers use to distribute products on the Steam platform. It supports DRM (digital rights management), multipliers, video streaming, game matching, an achievement system, in-game voice and chat, microtransactions, statistics, cloud , and sharing of content created by the Steam Workshop community.
From late August through September 2023, there has been an increased number of reports of compromised Steamworks accounts and the sending of malicious versions that infect gamers with malware.
Valve assured the gaming community that the impact of these attacks was limited to a few hundred users, who were individually notified of the potential breach through notifications sent by the company.
To address this issue, Valve will enforce a new SMS-based security check, effective October 24, 2023. Game developers will need to pass this check before upgrading their game to the default release branch (not to beta builds).
The same requirement will be enforced when someone tries to add new users to the Steamworks Partner Group, which is already protected by email confirmation. Starting October 24, the group admin will have to confirm the action with an SMS code.
See also: Diablo IV is coming to Steam on October 17th
“As part of a security update, any Steamworks account configured to run on the default/public branch of a program will need to have a phone number associated with their account so that Steam can send you a verification code via text before you can continue,” announcement .
“The same will apply to any Steamworks account that needs to add new users. This change will take effect on October 24, 2023, so make sure you add a phone number to your account now.“
“We also plan to add this requirement to other Steamworks actions in the future.“

For those using the SetAppBuildLive API, Steam has updated it to require a steamID for confirmation, especially for changes to an app. Using 'steamcmd' to enable releases is no longer applicable for managing the default branch of apps.
Valve also says there will be no workaround for developers who don't have a phone number, so they need to find a way to receive SMS so they can continue publishing on the platform.
Are there alternative methods to deal with these updates?
In answer to this question, there are a few ways besides SMS confirmation that Steam can use to combat software updates containing malware.
See also: Qualcomm: Its new chips want to bring the power of Steam Deck to Android
Update user confirmation
One of the most popular alternatives is to update the user verification system by adding multiple layers of verification. For example, the platform could require users to verify their identity via two or more methods, such as SMS and entering a unique personal code.
Creating default protected attributes
New software updates could also be protected from malware introduction by creating default protected features. For example, Steam could provide a secure environment for delivering new updates by requiring the use of trusted systems.
Strengthening user education
Finally, Steam could focus on strengthening user education on security . By implementing various techniques, such as encouraging the use of secure channels for downloading updates and raising awareness about the threat of malware, users can play an active role in protecting themselves from infected updates.
Source: bleepingcomputer
