- User-made maps from Steam top-seller Meccha Chameleon have been found to contain malware, coinciding with the hacking of the game's official Discord server.
- The year's top indie hit Meccha Chameleon has infected players with viruses due to compromised user-created content.
- Hackers executed a malware attack on the biggest game of the year, allowing them to take over users' PCs.
- The developers of Meccha Chameleon released an urgent update 3.1.0 to close a critical vulnerability that allowed users to download malware disguised as maps on Steam Workshop.
- During the investigation, a system engineer's PC was infected with malware, leading to the compromise of the developers' official Discord server.
- The hacker bypassed the engineer's two-factor authentication on Discord, altering server permissions and banning all staff members.
- The developers managed to regain control of the Discord server after contacting Discord, changing the highest privilege account to a different one.
- The game’s developers rolled out update 3.3.1 to further strengthen virus protection.
- An independent researcher named Feint discovered that certain user-created Steam Workshop maps contained malware that could install a Remote Access Trojan (RAT) on affected systems.
- The malware dropper style of attack allowed the installation of a RAT, giving the attacker the ability to remotely control compromised PCs.
- Players who launched affected Workshop maps were strongly recommended to perform a full malware scan and check for suspicious files.
- The Laser Tag Neon map was removed after the discovery, but additional infected maps like Chroma Grid Arena were uploaded.
- A July 8 Steam review highlighted the security risk posed by the game, noting that a player had their computer hacked while hosting a game.
Meccha Chameleon, a top-selling indie game, is facing a serious security crisis as user-created maps have been found to contain malware, specifically a Remote Access Trojan (RAT). This alarming discovery coincided with a hack of the game's official Discord server, which has over 100,000 members.124579

The issue was first reported by cybersecurity researcher Feint, who revealed that certain maps, including Laser Tag Neon, successfully bypassed Steam Workshop's automated scans. When launched, these maps would execute a script that installed the RAT, allowing hackers to remotely control infected PCs. Following this, the developers released urgent updates, including version 3.1.0, to patch the vulnerabilities that allowed the malware to spread.3612
In a statement, the developers reassured players that the game itself is safe, stating, “The game itself is not affected.” However, the hack led to the compromise of the developers' internal systems, with hackers bypassing two-factor authentication to take control of the Discord server. The team is currently working with Discord support to regain access, but the chances of recovery are deemed minimal.
Players are strongly advised to perform full malware scans and check for suspicious files on their systems. A recent Steam review highlighted the severity of the situation, warning that a player’s computer was hacked during gameplay. The developers are committed to enhancing security measures, with the latest update 3.3.1 aimed at further strengthening virus protection.811
“The developers released update 3.1.0 to close a critical vulnerability that allowed malware to be downloaded disguised as maps. An independent researcher, Feint, discovered that a custom map called Laser Tag Neon successfully passed Steam's automated scan, leading to the infection of players' systems.”
