A fake Steam login page copies Steam's sign-in form pixel for pixel. It sits on a domain the scammer owns and it opens when you click a phishing link. Everything you type goes to the scammer, who can then log into your real account. Some fake pages even relay the Steam Guard code you enter in real time, so the login works for them while the page shows you an error.
The most convincing version is a fake pop-up. The page draws a small window inside the browser tab that looks like a separate Steam login popup, complete with a fake address bar showing steamcommunity.com. Because it is just part of the web page, dragging it outside the tab is impossible, and the real address bar of the browser still shows the scam domain.
How do I tell a fake Steam login page from the real one?
Check the real address bar at the top of your browser, not any address text inside the page. The real login lives at steamcommunity.com or store.steampowered.com with a padlock icon. Try to drag the login window outside the browser tab. A real popup moves as its own window; a fake one is stuck inside the page.
Try typing a wrong password on purpose. A fake page often accepts anything, or shows a generic error, because it is only collecting text. Also notice how you got there. If you arrived through a link in chat or an email, assume it is fake until you prove otherwise.
What if I already logged in on a fake page?
Change your Steam password from a bookmarked real Steam page, deauthorize all other devices, and check steamcommunity.com/dev/apikey for a key you did not create. Look at your trade history. If CS2 items left your account in the last 7 days, you can reverse those trades through trade protection, which also locks trading for 30 days.
The safest habit is to never log in through a link. Keep Steam logged in on your own browser and use the scam link checker on anything you are unsure about. The fake Steam login pages guide has screenshots of the common fakes.