Meccha Chameleon Malware Spreads via Steam Workshop
Players of the indie game Meccha Chameleon recently encountered a dangerous security threat. Specifically, malicious actors delivered a malware dropper disguised as custom Steam Workshop maps. Furthermore, the incident escalated when attackers hijacked the official Discord server.
Malicious Custom Maps Discovered in Steam Workshop
Security researcher Feint first discovered the issue after receiving complaints from acquainted gamers. Players reported that command prompt windows briefly flickered during map downloads. Subsequently, an investigation revealed that a custom map titled Laser Tag Neon contained a malware dropper.
Interestingly, this infected map had successfully passed Steam Workshop’s automated screening. Later, the attacker replaced Laser Tag Neon with another malicious map named Chroma Grid Arena. According to a technical breakdown published by security researcher Feint, the payload operated as a subtle background dropper. Consequently, developers advise recent players to scan their systems with anti-malware software immediately.
Developer Response and Emergency Patch 3.1.0
Meccha Chameleon developer Haganeiro responded swiftly by releasing game update 3.1.0. This critical patch eliminated the exploit vector used by custom maps. Furthermore, developers neutralized the malicious code across both updated and legacy game versions.
Discord Server Hijacked Following Backup PC Compromise
Unfortunately, security troubles escalated while the developer team patched the game. The malware compromised a systems engineer’s backup computer. Subsequently, the attacker bypassed two-factor authentication, revoked employee administrative privileges, and seized control of the Discord server.
The official Discord server hosted nearly 100,000 community members. Developers immediately contacted Discord support to recover administrative control. Meanwhile, the compromised computer underwent complete remediation. Fortunately, this device lacked access to source code repositories.
Community Safety Recommendations
Developers urge players to avoid clicking links on the compromised Discord server. Although the game client is now secure, the attacker still controls the Discord community. Therefore, players must remain vigilant against phishing attempts and further malware distribution.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.