Steam Workshop malware campaign targets Meccha Chameleon

Researchers identified malicious Steam Workshop maps for the co-op game Meccha Chameleon that were used to install malware on players' PCs. Players first noticed a brief Command Prompt window appearing while loading matches with certain community-made maps, prompting an investigation. The first map linked to the attack, Laser Tag Neon, was found to write a batch file to the player's Windows Documents folder before launching a hidden PowerShell process that attempted to download a second-stage script from a remote server. A second map, Chroma Grid Arena, was later identified and also taken down. The malicious blueprint was hidden inside Unreal Engine asset metadata within a service file called AssetRegistry.bin under a name disguised as an innocuous lighting system, allowing it to pass Workshop moderation.
Discord server hijack fuels disinformation campaign
While the developers investigated the malicious Workshop content, the malware reached an isolated testing PC, allowing attackers to bypass two-factor authentication on a systems engineer's Discord account. The attackers seized control of the official Meccha Chameleon Discord server and banned the entire development team at once. Whoever took over the server began posting announcements impersonating the studio, including false claims that the developers themselves built a backdoor into the game and urging players to uninstall the game within 24 hours. The developers have contacted Discord support and warned players not to trust anything posted on the compromised server, not to click any links, and not to join any claimed "new official" servers.
Developer patches vulnerability and confirms game is safe
The developers released version 3.1.0 on July 25, 2026, which disables execution of third-party code in all Workshop maps, including those uploaded before the patch, rendering older malicious maps harmless. The studio confirmed the game itself was never compromised and that the incident was strictly limited to a single admin account's Discord being compromised. Meccha Chameleon launched in mid-June 2026 and has sold more than 15 million copies on Steam, making it one of the year's biggest indie hits. Valve has not publicly commented on the incident.
Recommended safety steps for affected players
Players who subscribed to a malicious map but never launched it are not believed to be at risk. The developers and researchers recommend updating the game to version 3.1.0, unsubscribing from any unfamiliar Workshop content, and running a full malware scan with reputable security software. Users are also advised to check their Documents and Temp folders for unfamiliar batch files and to review startup items and the task scheduler for unknown entries. Coverage noted that the installed payload was a Remote Access Trojan, or RAT, capable of allowing remote control of infected systems.
Dinoblade draws attention on Steam
A new indie title dubbed Dinoblade from developer Team Spino drew attention on Steam for blending Jurassic Park-style dinosaur themes with Elden Ring-style action RPG mechanics. Coverage described the crossover concept as "doomed to succeed," reflecting interest in combining dinosaur survival with soulslike design.
Share this article







