Malicious Workshop maps exploited a vulnerability in Meccha Chameleon’s mod system
Players who launched two affected community maps before the security patch are being advised to scan their PCs, while the developers stress that the official game files were never infected.
Malicious community maps uploaded to the Steam Workshop reportedly targeted players of MECCHA CHAMELEON, using a vulnerability in the game’s mod system to write and execute files outside the game itself.
The maps identified during the investigation were Laser Tag Neon and Chroma Grid Arena. Both have since been removed, and the developers released a security update intended to prevent Workshop maps from running unrelated files.
This was not malware embedded in the official game download, and there is no indication that the Steam client itself was compromised. The attack relied on malicious user-created content being launched through MECCHA CHAMELEON’s mod-map system.
The Meccha Chameleon Steam Workshop hosts user-created maps, including custom locations and themed environments.
The incident follows growing concern around malware distributed through gaming communities, fake playtests, and compromised accounts. We recently covered how Steam and Discord scams are becoming harder to identify, particularly when content appears to come from a familiar platform or community.
Want more player-safety news and practical gaming guides?
Get more gaming security alerts, news, reviews, interviews, guides, and independent coverage from Fix Gaming Channel.
Join Our Newsletter
Stay updated with the latest interviews, previews, guides, and gaming news.
How the malicious maps worked
The issue was investigated by a security researcher using the name Feint after players reported seeing a command prompt window briefly appear while a custom map was loading.
According to the researcher’s technical analysis, the Workshop content contained hidden logic that wrote a batch file into the player’s Documents folder.
The file then launched a hidden PowerShell process and attempted to download and run a second script from an external server.
The second-stage payload was later recovered and identified as a Remote Access Trojan, commonly known as a RAT. Malware of this type can potentially give an attacker remote control over an infected computer.
Security updates closed the vulnerability
Version 3.1.0 of MECCHA CHAMELEON, released on July 25, included what the patch notes described as a “security patch for MOD maps.”
The developers followed this with version 3.2.0, stating that the issue had been resolved and that Workshop maps could no longer execute unrelated files such as malware.
The team also said the fix had been confirmed with Steam Support.
The developers have repeatedly stressed that the official game files were not infected. The security problem involved malicious community maps exploiting the way mod content was handled before the patch.
What affected players should do
Players should update MECCHA CHAMELEON to the latest available version before launching any additional Workshop content.
Anyone who launched Laser Tag Neon, Chroma Grid Arena, or another suspicious custom map before version 3.1.0 should run a full malware scan.
The researcher also recommends checking the Documents and temporary-file folders for recently created or unfamiliar batch files.
The malicious code reportedly executed when the affected map was launched. Players who only subscribed to one of the maps but never started a match using it should still unsubscribe, but the researcher says subscribing alone did not trigger the malware.
Anyone who discovers malware or suspicious account activity should avoid entering new passwords on the affected PC until it has been properly cleaned. Our guide on what to do when a Steam account is compromised includes additional cleanup steps.
The official Discord server was also compromised
A related incident affected the official MECCHA CHAMELEON Discord server. According to the developers, a system engineer’s spare testing PC became infected while the team was investigating and patching the malicious map issue.
The attacker reportedly gained access to the engineer’s Discord account, bypassed two-factor authentication, changed server permissions, and removed the official staff.
The developers said the affected testing PC had no access to the game’s source files and was completely wiped and reformatted.
The official server was restored on July 26, with the team confirming that the attackers had been banned.
MECCHA CHAMELEON
Release: June 9, 2026
Genre: Casual, Multiplayer, Hide-and-Seek
Developer / Publisher: lemorion_1224
Platform: PC — Steam
Related Reading
Steam Account Stolen? What to Do First
Steam and Discord Scams Are Getting Smarter
BlockBlasters Pulled From Steam After Alleged Malware
Written by Ronny Fiksdahl, Founder & Editor of Fix Gaming Channel.
Send corrections, tips, press releases, or developer stories to contact@fixgamingchannel.com.
Support independent games coverage on Ko-fi.
