As I understand it, Steam has a report feature on their store page for reporting games. Presumably that goes to a person that looks at it.
I think to upload games to Steam you also need to prove your identity. Which means if you do upload malware, then it's easy to track you down.
Of course, that takes time and things can slip through the cracks. Steam games are still full programs that run on your computer and can do anything a regular program can do, there's no sandboxing.
Treat them like you would apps on the Google Play store; assume that they're mostly safe but also give additional scrutiny to ones with low review counts or AI generated images.