Hackers Hide Malware in Meccha Chameleon Steam Workshop Maps

Players jumping into Meccha Chameleon’s colorful hide-and-seek matches this past week got more than a quick round of camouflage. A handful of community-made Steam Workshop maps quietly turned their Windows PCs into targets, dropping malware the moment the maps loaded. The question that followed was simple and unsettling: How did a community-created game map become the gateway to malware and misinformation?

The trouble started around July 24, 2026, when independent researcher Feint noticed something odd. Friends reported a command prompt window flashing briefly while Steam downloaded a custom map called “Laser Tag Neon.” Digging into the files, Feint found the map abused Unreal Engine Blueprint logic. Disguised as an ordinary ambient controller, the Blueprint wrote a batch file into the user’s Documents folder the instant the map loaded. That file then launched a hidden PowerShell process and reached out to an external server for a second-stage script. Later analysis confirmed the payload installed a Remote Access Trojan, giving attackers persistent control of infected machines. Other maps, including “Chroma Grid Arena,” followed a similar pattern. They passed Steam’s review because they contained no obvious executables only standard Unreal assets.

The base game itself was never compromised. Developer lemorion_1224 (also associated with Haganeiro) moved quickly. “The game itself is 100% SAFE and virus-free,” the team stated. Updates 3.1.0 and 3.2.0 closed the vulnerability that let Workshop maps execute unrelated files. Steam Support confirmed the fix made such execution impossible. Malicious maps were disabled or removed.

The damage did not stop there. While investigating the maps, a system engineer’s spare testing PC became infected. Attackers used that foothold to bypass the engineer’s Discord two-factor authentication, seize the official Meccha Chameleon server nearly 100,000 members strong ban staff, and post false claims that official updates contained malware. The developers denied every claim.

“This statement was made solely to cause panic and mislead players,”

lemorion_1224 wrote. Steam’s infrastructure, they noted, prevents anyone from publishing a game update simply by compromising a single PC. The team is working with Discord Support and has prepared to launch a new server if the original cannot be recovered.

For players the advice is straightforward. Update to the latest version. If you loaded any suspicious Workshop content especially maps from brand-new accounts with comments disabled run a full malware scan and check your Documents folder for unexpected .bat files. Stick to popular, well-reviewed maps from established creators. Ignore the compromised Discord until the developers regain control or announce a new one.

Meccha Chameleon’s rapid rise to more than 15 million copies made its Workshop an attractive target. The episode serves as a clear warning for the millions of PC gamers who regularly download community content. User-generated maps and mods remain a powerful feature, but they also create an attack surface that automated reviews can miss.

Latest Posts

[democracy id="16"] [wp-shopify type="products" limit="5"]