< Back to all clusters
[TECHNOLOGY] · 8 sources

started · updated

MECCHA CHAMELEON Patch Closes Steam Workshop Malware Exploit

A community‑created map titled “Laser Tag Neon” for the indie game MECCHA CHAMELEON was found to contain a hidden Unreal Engine Blueprint that wrote a batch file, invoked PowerShell, and downloaded a second‑stage payload called steamb.bat. The payload installed a Remote Access Trojan, giving attackers control of affected Windows PCs. Independent researcher Feint uncovered the chain after players reported brief command‑prompt windows during map loading.

In response, the developers released version 3.1.0, which patches the mod‑loading vulnerability that allowed the malicious code to execute. Steam removed the identified malicious map and other flagged uploads, though similar submissions may still appear. During the investigation, a backup computer used by a system engineer was compromised; the attacker leveraged it to bypass Discord two‑factor authentication, seize the game’s official Discord server, and ban staff members. The developers maintain that the core game code remains clean and that the compromised machine had no access to source files or Steam developer accounts.

Entities

Discord · Feint · Laser Tag Neon · Meccha Chameleon · Valve Corporation