![]()
Fifteen million copies sold, and now a security scare nobody saw coming. Meccha Chameleon, the hide-and-seek painting game that’s been the runaway “friendslop” hit of 2026, just became the latest target of Steam Workshop malware, and the story gets messier the deeper you look.
It started with something small. A few players noticed a command prompt window flash briefly on their screens while Steam was quietly downloading a custom Workshop map. That’s it. No crash, no error message, nothing that would normally make anyone panic. But a security researcher who goes by Feint decided to dig into it anyway, and what they found was a lot uglier than a simple graphical glitch.
How The Meccha Chameleon Malware Actually Worked
Feint’s breakdown, published on Medium, walked through exactly how a Workshop map called Laser Tag Neon slipped past Steam’s own review process. On the surface, the files looked completely normal. Standard Unreal Engine 5 asset containers, no obvious executables, nothing that would trip an automated scanner. I’ve read a lot of malware writeups over the years, and this is one of those cases where the disguise was almost impressively boring.
Buried inside the map was a Blueprint actor carrying an outdated internal name, dressed up to look like a harmless ambient controller. Once the map loaded, that Blueprint quietly wrote a batch file into the victim’s Documents folder and used PowerShell to reach out to an external server for a second-stage payload. During Feint’s own testing, that second download returned a 404 error, so the final piece of the puzzle never actually landed on their machine.
Other analysis of the recovered script pointed toward a Remote Access Trojan as the intended payload, though because the live download failed, the full picture of what attackers were actually after is still murky.
What really stood out to me was the account behind the upload. It was only about a week old, and it had comments and ratings disabled on the listing, which meant anyone who got hit had no easy way to warn other players. That’s not an accident. That’s a setup built specifically to avoid scrutiny.
A Game or Map Should Never Touch Files Outside Its Folder
Here’s the thing that nobody talks about enough. A Workshop map executing scripts outside of its own game directory is, by itself, a massive red flag. Feint said as much directly, and honestly, that’s the single fact that should worry every Steam user reading this, regardless of whether they’ve ever touched Meccha Chameleon. Sources suggest a second map, Chroma Grid Arena, appeared shortly after Laser Tag Neon got reported, which hints this wasn’t a one-off upload but a pattern the same actor was ready to repeat.
Meccha Chameleon’s developer, Haganeiro, confirmed the issue publicly on X and moved fast. According to the studio’s own statement, the vulnerability in the custom maps was fixed in update 3.1.0, and there have been no further reports since players applied the patch. That’s a genuinely quick turnaround for an indie team, and I actually think it deserves some credit given how chaotic the rest of the week turned out to be for them.
Then The Discord server got hacked too.
If the malware map was the whole story, this would already be a rough week. It wasn’t. While the dev team was actively investigating and patching the malicious map, a system engineer’s own PC got infected. From there, things spiraled. According to reports from the community, the attacker used that infection to bypass the engineer’s two factor authentication on Discord, changed server permissions, and banned every staff member from their own community hub.
The official statement was blunt about it. The game itself was not affected, but the team said they had completely lost the ability to take any action on their own Discord server and were waiting on Discord Support to help them regain control. When I first heard about this angle, I didn’t think much of it, but after digging in, I changed my mind completely. This wasn’t two unrelated incidents happening to land in the same week. It was one security failure cascading directly into another, which is honestly a much scarier scenario than a single bad map.
This Isn’t The First Time Steam Workshop Malware Has Shown Up
This is one of those things I genuinely got excited about the moment I saw the pattern, mostly because it confirms something security researchers have been warning about for a while. Just last month, Kaspersky flagged a nearly identical scheme running through Wallpaper Engine, another wildly popular Steam app, where infected animated wallpapers were downloaded thousands of times before anyone caught on. Valve pulled those files but openly warned that similar incidents could keep happening.
If the current trajectory holds, it looks like Workshop content across multiple popular games is becoming an increasingly attractive target precisely because it slips past automated review and relies on players trusting community creators by default. Industry insiders hint that as more indie hits pull in Meccha Chameleon level numbers, attackers will keep chasing whichever game has the biggest, most trusting audience that week.
What You Should Actually Do
If you’ve played any custom Meccha Chameleon maps recently, it’s worth a few minutes of caution. Check your Documents folder for any unfamiliar .bat files. Look through your Startup entries and Task Scheduler for anything you don’t recognize, since persistence mechanisms like these are exactly how malware sticks around after a reboot. Run a proper antivirus scan. And if you only subscribed to a suspicious map without ever launching it, you’re likely fine, since Feint’s analysis confirmed the malicious code only executed once you actually loaded into the match.
The broader lesson here isn’t really about one indie game having a bad week. It’s that Steam Workshop, for all its convenience, still runs on a review process that a patient attacker with a week-old account can quietly work around. Meccha Chameleon patched its hole fast, and that matters. But between the malware map and the Discord takeover that followed it, this whole saga is a reminder that a platform hosting fifteen million players’ worth of goodwill still needs to earn that trust one workshop upload at a time.