Meccha Chameleon Update 3.1.0 Patches Workshop Malware Exploit After Discord Server Hack

Ali Ahmed Akib
By Ali Ahmed Akib
8 Min Read
Image Credit: lemorion_1224

The biggest indie success story on Steam this year just had the worst weekend imaginable. Malware was found hiding inside Meccha Chameleon Workshop maps, and the fallout ended with the game’s official Discord server in a stranger’s hands.

In brief

  • A community Workshop map called Laser Tag Neon was found to be a malware dropper, and it had already passed Steam’s Workshop review
  • The malicious code only ran when players actually loaded the map in a match, not when they subscribed to it
  • Researcher Feint later recovered the second stage and reported it installed a Remote Access Trojan capable of giving an attacker remote control of an infected PC
  • Developer Haganeiro patched the underlying vulnerability in Meccha Chameleon update 3.1.0
  • While investigating the malware, a system engineer’s backup PC got infected, and the attacker used it to bypass Discord 2FA, seize server permissions, and ban every staff member
  • The developers insist the game itself is clean and that the infected machine had no access to source files or Steam developer accounts

What happened with Meccha Chameleon’s Steam Workshop maps?

This all started with something small and easy to ignore. Independent researcher Feint began digging after reports of command prompt windows briefly appearing while players loaded custom Meccha Chameleon maps. Most people would shrug that off as a Steam download quirk, but Feint did not.

Mechacameleon Malware

On July 24, Feint published a breakdown on Medium showing how a community map named Laser Tag Neon, despite having passed Workshop review, would flash a command prompt window and start pulling down a script to install malware on Windows PCs. On the surface, the files were completely normal, with standard Unreal Engine 5 asset containers and no obvious executables or scripts. The real problem was a Blueprint actor with a naming mismatch buried inside the map’s metadata.

There were warning signs around the uploader too, if you knew where to look. The Steam account behind the map was only about a week old and had comments and ratings disabled on the listing, which made it much harder for anyone who noticed something wrong to warn other players.

How the malicious Meccha Chameleon map worked

Feint found that Laser Tag Neon contained code capable of writing a batch file into the player’s Documents folder. That file then tried to use PowerShell to download and run a second payload from an external server.

Feint’s own read on it was blunt, and honestly hard to argue with. There is no legitimate reason for a Workshop map to write a batch file into a user’s Documents folder and then use PowerShell to fetch and run another one from the internet. A map is supposed to be geometry and assets. It has no business touching anything outside the game’s own folder.

Mecha cameleon new update
Image Credit: lemorion_1224

At first nobody knew what the second stage actually did because the download link had already gone dead. Feint eventually recovered and analyzed the second-stage payload and reported that it installed a Remote Access Trojan, the kind of thing that hands an attacker persistent remote control over a compromised machine.

One important detail that saved a lot of people: subscribing to a malicious map on its own was not enough to trigger anything. The map had to be launched in a match.

Meccha Chameleon update 3.1.0 patches the Workshop exploit

The developers moved fast once the report went public. Haganeiro confirmed the vulnerability was fixed in Meccha Chameleon update 3.1.0, saying there are no issues once the patch is applied. The team also said the malware had been disabled on the identified maps, including for players who had not installed the update yet.

The fix targeted the execution path that let Workshop maps write and run files on a player’s machine in the first place, which means this was not just one bad actor slipping past a lazy moderator. Something in how the game loaded community content made this possible.

Taking down the map did not end it either. Feint updated the report to note that another map called Chroma Grid Arena had been uploaded in its place.

How hackers took over the official Meccha Chameleon Discord server

Here is where the story goes from bad to genuinely rough. While investigating the malicious maps, a system engineer working on the game used a backup computer and ended up infecting it with malware. The attacker used that foothold to reach the engineer’s Discord account, bypass two-factor authentication, change server permissions, and ban the game’s staff members from a server with close to 100,000 people in it.

Developer LEMORION described it plainly in a statement. The hacker bypassed the engineer’s two-factor authentication on Discord, altered the server permissions, and banned all the staff members.

The team’s Steam post admitted they were completely unable to take any action on their end, that they had contacted Discord Support, and that they would set up a new server if the original could not be recovered.

Then the attacker started playing games with the community. False announcements went out through the hijacked server claiming the latest update contained a remote access Trojan and that users needed to follow specific steps to fix it. The developers said they never implemented anything of the sort and that the statement existed purely to cause panic and mislead players. Classic bait, and the kind that catches people who are already spooked by legitimate malware news.

Is Meccha Chameleon safe to play right now?

The developers have been firm on this. Their statement stressed that the game itself is safe and virus-free, that the incident was limited to a single admin account’s Discord being compromised, and that the infected PC was a spare testing machine with no way to access or edit game source files, something they say they reconfirmed through logs. The machine has since been completely wiped and reformatted.

They also pointed out that even a compromised PC could not push a game update, since Steam’s developer infrastructure does not work that way. And because the game and Discord are not integrated in any way, being on the server does not put your copy of the game at risk.

A replacement community server was created while the developers waited on Discord Support, and players were told not to trust announcements or click links posted in the original one.

Community content is one of the best things about PC gaming. It is also the softest surface an attacker can aim at, and until platform-level scanning catches up, the burden of noticing a week-old account with comments disabled falls on players.

ali ahmed akib
By Ali Ahmed Akib Editor-in-chief
Follow:
Ali Ahmed Akib is the Co-Founder and Editor-in-chief of GameRiv. Akib grew up playing MOBA titles, especially League of Legends and is currently managing the editorial team of GameRiv.