MECCHA CHAMELEON Malware: Workshop Map to Discord Takeover

PhishFort Team
PhishFort Team
• 7 min read
MECCHA CHAMELEON Malware: Workshop Map to Discord Takeover

In July 2026, a malicious Steam Workshop map for the game MECCHA CHAMELEON used a flaw in the game’s mod loading to install a Remote Access Trojan (RAT) on players’ PCs. The malware later compromised a test machine used by one of the game’s engineers, and attackers used that foothold to take over an administrator account on the official Discord server, which has nearly 100,000 members. The developers patched the flaw in version 3.1.0, and Steam removed the malicious maps.

Summary of the hack:

  1. Two Steam Workshop maps, Laser Tag Neon and Chroma Grid Arena, carried hidden Unreal Engine 5 Blueprint logic that ran as soon as a player loaded the map.
  2. The Blueprint dropped a batch file that used PowerShell to download a second-stage script, which installed a persistent RAT.
  3. Attackers reached the official Discord through a compromised test machine, bypassed two-factor authentication (2FA) on an admin account, changed server permissions and banned official staff.

Players who loaded custom maps before updating should scan for malware, check for unauthorized batch files and startup entries, and update to version 3.1.0 or later.

What happened to MECCHA CHAMELEON players?

Players of MECCHA CHAMELEON, a multiplayer game on Steam, were infected with malware after loading community-made maps from Steam Workshop, Valve’s platform for sharing user-created game content. Independent reverse engineer Feint documented the campaign in July 2026, after players reported a Command Prompt window flashing when a custom map loaded.

Command Prompt window opening while a MECCHA CHAMELEON Workshop map loads

The first map, Laser Tag Neon, had passed Workshop review. A second upload, Chroma Grid Arena, appeared as a replacement and was also removed (Notebookcheck).

The flaw was in the game, not in Steam Workshop itself. MECCHA CHAMELEON’s asset-execution logic let map content run code, which turned a normal community feature into a malware delivery channel.

How did a Workshop map install malware?

The MECCHA CHAMELEON attack chain ran automatically once a player opened the infected map:

  1. A Blueprint (Unreal Engine’s visual scripting system) named BP_RCE_Test, later renamed BP_AmbientController, fired on the map’s BeginPlay event.
  2. The Blueprint wrote a file called s.bat to the player’s %USERPROFILE%\Documents folder. The file was a JSON and batch polyglot: valid JSON that also runs as a batch script.
  3. The script relaunched itself and opened a hidden PowerShell session with an execution-policy bypass.
  4. PowerShell downloaded a second-stage script from a hardcoded command-and-control (C2) server.
  5. The second stage installed a persistent RAT, giving the attacker remote control of the PC.

Source: Feint’s analysis as summarized by Notebookcheck.

Unreal Engine Blueprint from a MECCHA CHAMELEON Workshop map that writes a batch file to disk

How did attackers take over the official Discord server?

Attackers took over the official MECCHA CHAMELEON Discord by compromising a spare test machine that a system engineer was using to investigate the malware. From that foothold, they bypassed 2FA on an administrator’s Discord account, changed server permissions and banned official staff members (Notebookcheck).

The server has nearly 100,000 members, and access was later restored. Public reports do not explain how the 2FA was bypassed. The development team said the game’s source code and production systems were not compromised.

Why does a hijacked official channel matter for a brand?

An official community server is a brand-owned channel: members trust its announcements because they come from the brand. Whoever controls an admin account there can post announcements, decide who can speak and remove the moderators who would normally flag abuse. In the MECCHA CHAMELEON case, attackers used admin access to change permissions and ban official staff.

The pattern goes beyond one game. In June 2026, malicious Wallpaper Engine application wallpapers on Steam Workshop delivered several types of malware (SC Media). Both incidents abuse a channel users already trust, the same logic behind browser extension hijacks and other supply chain attacks.

When the trusted channel belongs to the brand, the damage lands on the brand’s reputation even if its core infrastructure was never breached. The same risk applies to hijacked brand accounts on X, Telegram or Instagram, covered in PhishFort’s guide to social media impersonation and in a verified account takeover case. A Threat Analyst at PhishFort said:

The Workshop map was only the entry point. The real damage started when attackers reached an admin account on the official Discord, because from that moment they could speak in the brand’s voice to nearly 100,000 people. Studios should protect their community channels with the same care as their login pages.

What should players and IT teams check?

Indicators below are as of September 28, 2026. The sources reviewed did not publish command-and-control domains, so there is nothing to defang.

Indicator Where to look Why it matters
Workshop maps named Laser Tag Neon or Chroma Grid Arena Steam Workshop subscriptions and download history Both carried the malicious Blueprint and have been removed
s.bat %USERPROFILE%\Documents The first-stage file the map dropped
Unauthorized .bat files %TEMP% Possible leftovers of the download chain
Unknown scheduled tasks or startup entries Task Scheduler and Startup apps Where a persistent RAT survives restarts
Game version below 3.1.0 Steam library, game properties Earlier versions let Workshop maps launch external processes

How should players, studios and security teams respond?

Players

  1. Update MECCHA CHAMELEON to version 3.1.0 or later, which blocks Workshop maps from launching external processes.
  2. If you loaded custom maps before updating, run a full antivirus scan.
  3. Check the locations in the indicators table and remove any unauthorized files or startup entries.
  4. Change passwords for accounts used on that PC and sign out other active sessions, since a RAT can capture what happens on the machine.

Game studios and community managers

  1. Treat user-generated content as code. Block maps and mods from launching external processes, the fix MECCHA CHAMELEON shipped in 3.1.0.
  2. Investigate suspected malware only on isolated machines that are never signed in to admin accounts for Discord, Steam, or social channels.
  3. Keep a recovery path for official community accounts: backup admins, platform escalation contacts, and a way to warn members through a second channel.
  4. Monitor for impersonation of the brand during and after an incident, when members are least sure which channel is real.

Corporate security teams

  1. Keep games and mods off corporate devices, including Bring Your Own Device (BYOD) machines used for work. One infected test machine was enough to reach an admin account in this incident.
  2. Alert on PowerShell launched with an execution-policy bypass by a game or launcher process.

PhishFort Brand Protection detects accounts, pages, and domains impersonating a brand across the web, social platforms, and app stores, and handles the takedown. See how it works for game studios and publishers.

No. The game crashes some Windows 11 users saw in August 2026 are a separate issue. After the August 11, 2026 security update KB5121003 for Windows 11 versions 24H2 and 25H2, Microsoft received reports that ARC Raiders, MARVEL Tōkon: Fighting Souls and THE FINALS froze, closed without notice, showed an EXCEPTION_ACCESS_VIOLATION error or restarted the device (Microsoft).

Microsoft associates the problem with RGB lighting peripherals or components that install drivers named like inpoutx64. It resolved the issue with a block that stops the inpoutx64 driver from loading, delivered automatically to consumer and unmanaged business devices. Enterprise-managed devices do not get the block automatically, so IT administrators apply the workaround published on the Windows release health site.

FAQs

Can a Steam Workshop map contain malware?

Yes, if the game lets map content execute code. In MECCHA CHAMELEON, a hidden Blueprint in a map wrote and ran a batch script that installed a RAT. The risk depends on how each game loads community content, not on Steam Workshop alone.

Is MECCHA CHAMELEON safe to play now?

Version 3.1.0 patched the vulnerability and prevents Workshop maps from launching external processes, and Steam removed the flagged maps. Players should update and stay cautious with maps from unknown uploaders, because new malicious uploads remain possible.

What is a Remote Access Trojan (RAT)?

A Remote Access Trojan is malware that gives an attacker remote control of an infected computer. In the MECCHA CHAMELEON campaign, the RAT was persistent, so it kept running after restarts until removed.

How did attackers get into the MECCHA CHAMELEON Discord?

They compromised a spare test machine an engineer used to investigate the malware, then bypassed 2FA on an administrator’s Discord account. With admin access, they changed permissions and banned official staff, and the server was later restored.

Should employees play games or install mods on work computers?

No. Games and mods add code the security team does not control, and a single infected machine can expose every account signed in on it. The rule applies to BYOD devices used for work too.

Sources