Another reliable source has just posted it.
Quote from http://scrap.tf/:
A recent major security hole has been discovered in TF2. It is not exactly clear how it works at this time, but there are a few reports of infected servers being able to download a file to your computer that contains a virus currently called "Trojan.SteamBurglar.1". All of this is currently unconfirmed by Valve or any security experts.
Here are some hotfixes you can use to stay away from this:
Avoid using the quickplay function, as you may end up on an infected server. Also avoid joining servers "with random numbers for name and the name changes after some time". Under options -> multiplayer you can toggle server downloads to mapsonly, or alternatively you can use the console command:
cl_downloadfilter mapsonly. As always, ensure you use an antivirus and don't click on untrustworthy links.
It is currently unclear whether this is TF2 only or across all source games. Report servers with weird names to Valve.
Stay safe!