
Meccha Chameleon Workshop maps hid malware that hijacked its Discord
Malicious Steam Workshop maps for Meccha Chameleon planted a Remote Access Trojan on players' PCs and ultimately helped attackers take over the game's official Discord server. Developer Haganeiro has patched the exploit in update 3.1.0.
A Workshop map with a hidden payload
Steam Workshop is one of those features PC players tend to trust almost by instinct. You see a fun-looking community map, you subscribe, you play it. That assumption of safety is exactly what someone exploited against Meccha Chameleon, the indie sensation that has been drawing a devoted crowd.
The trouble was first investigated by independent researcher Feint, who looked into reports of command prompt windows flashing on screen as players loaded custom Workshop maps, as reported by Dexerto. Feint traced the source to a Workshop upload called Laser Tag Neon. That map contained code capable of writing a batch file directly to a player’s Documents folder. The batch file then used PowerShell to reach out to an external server and pull down a second-stage payload.
The map was eventually removed. But someone had more plans. Feint later reported a second malicious upload appearing in its place, this one called Chroma Grid Arena.
The payload itself was serious
When Feint recovered and analyzed that second-stage payload, the findings were not reassuring. According to the researcher, it installed a Remote Access Trojan, the kind of software that gives an attacker persistent, ongoing control over an infected machine. Not a one-time data grab. Persistent. Remote. Control.
That distinction matters for anyone trying to assess their risk. If you loaded one of those Workshop maps in a live match before updating the game, a full malware scan is the appropriate next step. Feint also recommended manually checking your Documents and temporary folders for any recently created .bat files.
One important clarification from the researcher: simply subscribing to a malicious map was not enough to trigger infection. The content had to be launched in an actual match. So players who downloaded a suspicious map but never ran it may have gotten lucky.
The Discord server fell too
The damage did not stop at individual PCs. Developer account credentials appear to have been among the information stolen or leveraged through the attack. On July 25, community figure LEMORION posted in Japanese confirming that the Meccha Chameleon Discord server’s security had been breached, the server creator’s account had been taken over, and all administrators had been banned, leaving the team unable to respond from within the server. Discord had been contacted, and the community was asked to help by reporting the compromised server.
That is a particularly painful outcome for a small indie team. Losing control of your main community hub, watching your moderators get mass-banned, and being locked out while players look to you for answers is the kind of crisis that tests a studio’s relationship with its audience.
Haganeiro patches the exploit in update 3.1.0
Developer Haganeiro confirmed a fix was in place with Meccha Chameleon update 3.1.0. “The vulnerability in the custom maps described in today’s update 3.1.0 has been fixed, so there are no issues after applying it,” the developer stated, according to Dexerto. The team added that the malware had been disabled on the identified maps, covering even players who had not yet installed the update at the time.
For a game that has been riding genuine momentum, this is an ugly chapter. Workshop-based malware attacks are not unprecedented across PC gaming, but they remain relatively rare and tend to catch players off guard precisely because custom content pipelines feel like community spaces rather than attack surfaces. The Meccha Chameleon case is a useful reminder that any system allowing user-uploaded executable-adjacent content requires scrutiny, both from platforms and from the developers who enable it. Update 3.1.0 is out. If you play Meccha Chameleon, install it and check your folders.
What happened with the Meccha Chameleon malware?
According to Dexerto, malicious Steam Workshop maps for Meccha Chameleon contained code that wrote batch files to players' Documents folders and used PowerShell to download a Remote Access Trojan. The attacker eventually used a compromised developer account to take over the game's official Discord server and ban all administrators.
Is Meccha Chameleon safe to play now?
Developer Haganeiro confirmed the exploit was patched in update 3.1.0. The developer also stated the malware had been disabled on identified maps even for players who had not yet installed the update, though anyone who launched a suspicious Workshop map before updating is advised to run a full malware scan.
Do you get infected just by subscribing to a malicious Workshop map?
No. Independent researcher Feint reported that subscribing to a malicious map alone was not enough to trigger the malware. The infected content had to actually be launched in a match for the payload to execute.
What should affected players do?
Feint recommended running a full malware scan and checking the Documents and temporary folders for recently created .bat files. Players should also install Meccha Chameleon update 3.1.0 and avoid the original Discord server, which remained compromised at the time of reporting.
