You download a custom map. You load it up. Nothing looks wrong.
Then a black command window flashes on your screen for half a second — and disappears.
That's exactly what happened to players of Meccha Chameleon, and it turned into one of the messier Steam Workshop security messes we've seen in a while. A couple of infected maps. A compromised developer PC. A hijacked Discord server. All in one incident.
Let's break down what actually went down, because the details matter here.
A Map That Wasn't Just a Map

Two Workshop uploads — reportedly called Laser Tag Neon and Chroma Grid Arena — looked like normal Unreal Engine content. Nothing suspicious in the thumbnail. Nothing in the description.
But buried inside was a hidden Blueprint actor programmed to fire automatically the moment the map loaded.
Here's the part that should worry you: players didn't have to click anything. No installer. No "run this file" prompt. Just loading the map was enough to trigger the chain reaction.
A security researcher who goes by Feint picked up on the issue after players started noticing that flashing command prompt window. Digging into the files, Feint found that the hidden code could:
- Drop a batch file into the user's Documents folder
- Silently launch PowerShell in the background
- Reach out to an external server to fetch a second-stage payload
That second payload is where things get scary. Early attempts to analyze it hit a "missing file" error, which made it tough to pin down exactly what the attacker wanted. But later digging tied the delivery chain to remote-access malware — the kind that can hand an attacker near-total control over an infected machine.
Think about that for a second. A custom multiplayer map, something you'd normally treat like a free skin or a fun mod, was capable of quietly installing a remote-access tool on your computer.
The Game Itself? Still Safe
Before anyone panics and uninstalls Meccha Chameleon entirely — hold on.
The developers were clear on this point: the base game was never infected. The malware lived exclusively inside third-party Workshop content uploaded by bad actors, not in the game's own code.
"The game itself is 100% SAFE and virus-free," the official Meccha Chameleon account said while addressing the situation.
That's an important distinction, but it doesn't erase the bigger problem. The game's Workshop system allowed custom maps to do things a map should never be able to do — like execute files completely unrelated to the map itself. That's the real vulnerability, and it's the part that needed fixing.
Then It Got Worse — a Lot Worse
Here's where the story takes a turn nobody expected.
While the dev team was investigating the malicious maps, one of the game's own system engineers loaded a suspect file on a separate testing PC. That machine got infected in the process.
From there, the malware reportedly hijacked the engineer's active Discord session — and somehow slipped past two-factor authentication.
Wait, past 2FA? How?
This is the detail people keep glossing over. It's unlikely the attacker actually cracked the 2FA code itself. More likely, the malware stole an already-authenticated session token straight from the infected machine. If your session is already logged in, an attacker doesn't need your password or your one-time code — they just need your cookies.
Once inside, the attacker took over the official Discord server. They reportedly changed permissions and banned members of the dev team, locking legitimate staff out of their own community hub. Players were warned not to trust anything posted there during the takeover — no links, no downloads, no announcements.
The infected testing PC has since been wiped and reformatted, according to the developer.
What the Fix Looks Like
The team pushed out version 3.1.0, which closes the loophole that let Workshop maps execute unrelated files in the first place. The dangerous maps have been pulled from the Workshop entirely.
One small silver lining: based on what's been reported, simply subscribing to one of the malicious maps likely wasn't enough to trigger the infection. You had to actually load it in-game.
Still — if you played Meccha Chameleon before the patch and loaded any unfamiliar community maps, don't shrug this off.
If You Played Before the Patch, Do This
Seriously, take five minutes and run through this checklist:
- Run a full antivirus scan — Windows Security works fine, but any trusted tool will do.
- Check your Documents and Temp folders for random .bat files you don't recognize.
- Review Startup apps and Scheduled Tasks for anything unfamiliar.
- Change important passwords — but do it from a different, clean device.
- Sign out of all Discord sessions and regenerate your backup codes.
- Avoid any links posted through the compromised Discord server, even old ones.
- Update everything — Steam, Windows, and the game itself.
And here's a bigger point: if your antivirus flags something like remote-access malware or an info-stealer, changing your passwords on the same infected computer won't cut it. You need to clean the system — or wipe it completely — before you type in a single new password. Otherwise you're just handing the attacker your new credentials too.
The Bigger Lesson for Every Gamer
Steam Workshop runs on trust. You click subscribe, Steam grabs the files, and the game handles the rest. That convenience is exactly why it works so well — and exactly why it's risky.
Most Workshop content is completely harmless. This particular exploit relied on a flaw specific to how Meccha Chameleon processed its maps, not some universal Steam weakness. But it's a solid reminder: user-generated content should never get a free pass just because Steam is hosting it.
A few red flags worth watching for going forward:
- A brand-new uploader account with zero history
- Comments disabled on the map page
- Little to no community engagement or reviews
None of those guarantee malware. But together, they're worth a second look before you hit subscribe.
For now, Meccha Chameleon's specific hole has been patched. The bigger question — one that applies way beyond this one game — is how many other Workshop-supported titles have a similar weakness just waiting to be found.
Update first. Investigate second. Because sometimes the real threat in a multiplayer game isn't the other player.
It's the map.







