The breakout indie sensation Meccha Chameleon has responded to a serious cybersecurity incident after malicious Steam Workshop maps were found distributing malware capable of giving attackers remote control of players’ computers. The exploit targeted community-created content rather than the base game, prompting the developers to release emergency updates while warning players to avoid suspicious Workshop maps.
The incident comes as Meccha Chameleon continues its rapid rise in popularity, having reportedly surpassed 15 million copies sold within its first month. While the vulnerability has now been patched, the attack highlights the growing security risks surrounding user-generated content in PC games.
Malicious Steam Workshop maps installed remote access malware
According to independent security researcher Feint, several custom maps uploaded to the Steam Workshop contained hidden malware. The infected maps, including Laser Tag Neon and later Chroma Grid Arena, reportedly launched an invisible command prompt that downloaded a Remote Access Trojan (RAT) onto affected systems.
Once installed, the malware enabled attackers to access compromised PCs remotely. Feint advised anyone who played the affected maps to perform a complete malware scan and inspect their Documents and temporary folders for suspicious batch (.bat) files.
Following the discovery, developer lemorion_1224 quickly removed the vulnerable functionality through version 3.1.0, preventing additional Workshop maps from exploiting the same weakness.

Developers’ own PC infected during the fix
The incident escalated while the developers were working to resolve the vulnerability. In a statement posted on X, developer lemorion_1224 explained that one of the team’s system engineers became infected while addressing the malware issue.
“While fixing the issue of malware embedded in a MOD map, a system engineer’s PC got infected with malware,”
the developer wrote. The attackers then bypassed the engineer’s Discord two-factor authentication, gained administrative control of the game’s official Discord server, and temporarily banned staff members.
The developers urged players not to trust any messages or links shared through the compromised server, warning that the attackers could impersonate official staff.
Shortly afterward, the team confirmed it had regained control of the Discord community after working with Discord’s support team. The compromised administrator accounts were removed, server permissions were restored, and ownership was transferred to a secure account.
Security updates released as investigation continues
The developers have since released update 3.3.1, adding additional protections against similar attacks. While the exploit appears to have affected only users who launched infected Workshop maps, the total number of impacted players remains unknown.
The incident follows several recent malware-related cases on Steam, including the removal of malicious games from the platform. It also underscores the importance of downloading community-created content only from trusted creators and keeping games updated with the latest security patches.
