Meccha Chameleon Malware Spreads via Steam Workshop

Meccha Chameleon malware infection vector via Steam Workshop maps

Players of the indie game Meccha Chameleon recently encountered a dangerous security threat. Specifically, malicious actors delivered a malware dropper disguised as custom Steam Workshop maps. Furthermore, the incident escalated when attackers hijacked the official Discord server.

Malicious Custom Maps Discovered in Steam Workshop

Security researcher Feint first discovered the issue after receiving complaints from acquainted gamers. Players reported that command prompt windows briefly flickered during map downloads. Subsequently, an investigation revealed that a custom map titled Laser Tag Neon contained a malware dropper.

Interestingly, this infected map had successfully passed Steam Workshop’s automated screening. Later, the attacker replaced Laser Tag Neon with another malicious map named Chroma Grid Arena. According to a technical breakdown published by security researcher Feint, the payload operated as a subtle background dropper. Consequently, developers advise recent players to scan their systems with anti-malware software immediately.

Developer Response and Emergency Patch 3.1.0

Meccha Chameleon developer Haganeiro responded swiftly by releasing game update 3.1.0. This critical patch eliminated the exploit vector used by custom maps. Furthermore, developers neutralized the malicious code across both updated and legacy game versions.

Discord Server Hijacked Following Backup PC Compromise

Unfortunately, security troubles escalated while the developer team patched the game. The malware compromised a systems engineer’s backup computer. Subsequently, the attacker bypassed two-factor authentication, revoked employee administrative privileges, and seized control of the Discord server.

The official Discord server hosted nearly 100,000 community members. Developers immediately contacted Discord support to recover administrative control. Meanwhile, the compromised computer underwent complete remediation. Fortunately, this device lacked access to source code repositories.

Community Safety Recommendations

Developers urge players to avoid clicking links on the compromised Discord server. Although the game client is now secure, the attacker still controls the Discord community. Therefore, players must remain vigilant against phishing attempts and further malware distribution.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply