<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Steam - PhishFort | AI-Powered Brand Protection</title><link>https://phishfort.com/resources/blog/tag/steam/</link><description>PhishFort delivers agentic brand protection: detecting and eliminating phishing sites, fake apps, and impersonations across every digital channel.</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Tue, 29 Sep 2026 06:00:00 +0000</lastBuildDate><atom:link href="https://phishfort.com/resources/blog/tag/steam/index.xml" rel="self" type="application/rss+xml"/><item><title>MECCHA CHAMELEON Malware: Workshop Map to Discord Takeover</title><link>https://phishfort.com/meccha-chameleon-workshop-malware-discord-takeover/</link><pubDate>Tue, 29 Sep 2026 06:00:00 +0000</pubDate><dc:creator>PhishFort Team</dc:creator><guid>https://phishfort.com/meccha-chameleon-workshop-malware-discord-takeover/</guid><description><![CDATA[<p>In July 2026, a malicious Steam Workshop map for the game MECCHA CHAMELEON used a flaw in the game&rsquo;s mod loading to install a Remote Access Trojan (RAT) on players&rsquo; PCs. The malware later compromised a test machine used by one of the game&rsquo;s engineers, and attackers used that foothold to take over an administrator account on the official Discord server, which has nearly 100,000 members. The developers patched the flaw in version 3.1.0, and Steam removed the malicious maps.</p>]]></description><content:encoded><![CDATA[<p>In July 2026, a malicious Steam Workshop map for the game MECCHA CHAMELEON used a flaw in the game&rsquo;s mod loading to install a Remote Access Trojan (RAT) on players&rsquo; PCs. The malware later compromised a test machine used by one of the game&rsquo;s engineers, and attackers used that foothold to take over an administrator account on the official Discord server, which has nearly 100,000 members. The developers patched the flaw in version 3.1.0, and Steam removed the malicious maps.</p>
<p><strong>Summary of the hack:</strong></p>
<ol>
<li>Two Steam Workshop maps, Laser Tag Neon and Chroma Grid Arena, carried hidden Unreal Engine 5 Blueprint logic that ran as soon as a player loaded the map.</li>
<li>The Blueprint dropped a batch file that used PowerShell to download a second-stage script, which installed a persistent RAT.</li>
<li>Attackers reached the official Discord through a compromised test machine, bypassed two-factor authentication (2FA) on an admin account, changed server permissions and banned official staff.</li>
</ol>
<p>Players who loaded custom maps before updating should scan for malware, check for unauthorized batch files and startup entries, and update to version 3.1.0 or later.</p>
<h2 id="what-happened-to-meccha-chameleon-players">What happened to MECCHA CHAMELEON players?</h2>
<p>Players of MECCHA CHAMELEON, a multiplayer game on Steam, were infected with malware after loading community-made maps from Steam Workshop, Valve&rsquo;s platform for sharing user-created game content. Independent reverse engineer Feint <a href="https://medium.com/@FeintBE/workshop-map-for-meccha-chameleon-is-a-malware-dropper-full-breakdown-d1ac29565265" target="_blank" rel="noopener noreferrer nofollow">documented the campaign in July 2026</a>, after players reported a Command Prompt window flashing when a custom map loaded.</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1790608295651-pasted-image_hu_a3ad92089662e938.webp 480w, /img/1790608295651-pasted-image_hu_db11019f0093ce00.webp 768w, /img/1790608295651-pasted-image_hu_22a3f47a40e3c315.webp 1200w, /img/1790608295651-pasted-image_hu_47071909c2dcb8f0.webp 1600w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1790608295651-pasted-image.jpg"
          srcset="/img/1790608295651-pasted-image_hu_eef98e6b16a98242.jpg 480w, /img/1790608295651-pasted-image_hu_3feacf627715d4ee.jpg 768w, /img/1790608295651-pasted-image_hu_b1c547208b913abf.jpg 1200w, /img/1790608295651-pasted-image.jpg 1600w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt="Command Prompt window opening while a MECCHA CHAMELEON Workshop map loads"
          
          width="1600" height="1200"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p>The first map, Laser Tag Neon, had passed Workshop review. A second upload, Chroma Grid Arena, appeared as a replacement and was also removed (<a href="https://www.notebookcheck.net/Meccha-Chameleon-Workshop-malware-led-to-Discord-server-hijack-RAT-infections.1355649.0.html" target="_blank" rel="noopener noreferrer nofollow">Notebookcheck</a>).</p>
<p>The flaw was in the game, not in Steam Workshop itself. MECCHA CHAMELEON&rsquo;s asset-execution logic let map content run code, which turned a normal community feature into a malware delivery channel.</p>
<h2 id="how-did-a-workshop-map-install-malware">How did a Workshop map install malware?</h2>
<p>The MECCHA CHAMELEON attack chain ran automatically once a player opened the infected map:</p>
<ol>
<li>A Blueprint (Unreal Engine&rsquo;s visual scripting system) named <code>BP_RCE_Test</code>, later renamed <code>BP_AmbientController</code>, fired on the map&rsquo;s <code>BeginPlay</code> event.</li>
<li>The Blueprint wrote a file called <code>s.bat</code> to the player&rsquo;s <code>%USERPROFILE%\Documents</code> folder. The file was a JSON and batch polyglot: valid JSON that also runs as a batch script.</li>
<li>The script relaunched itself and opened a hidden PowerShell session with an execution-policy bypass.</li>
<li>PowerShell downloaded a second-stage script from a hardcoded command-and-control (C2) server.</li>
<li>The second stage installed a persistent RAT, giving the attacker remote control of the PC.</li>
</ol>
<p>Source: Feint&rsquo;s analysis as summarized by <a href="https://www.notebookcheck.net/Meccha-Chameleon-Workshop-malware-led-to-Discord-server-hijack-RAT-infections.1355649.0.html" target="_blank" rel="noopener noreferrer nofollow">Notebookcheck</a>.</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1790608335521-pasted-image_hu_5fa8e62b5bb64c6d.webp 480w, /img/1790608335521-pasted-image_hu_704c67d31b015cb4.webp 768w, /img/1790608335521-pasted-image_hu_9e08f01f87a54030.webp 1200w, /img/1790608335521-pasted-image_hu_74e9582376e266ff.webp 1600w, /img/1790608335521-pasted-image_hu_1f8203fea47a8416.webp 1693w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1790608335521-pasted-image.png"
          srcset="/img/1790608335521-pasted-image_hu_94a56fdc1e1bdf49.png 480w, /img/1790608335521-pasted-image_hu_380d69ee219fe712.png 768w, /img/1790608335521-pasted-image_hu_8f807757d15a3bdd.png 1200w, /img/1790608335521-pasted-image_hu_61f62a9b37eb57db.png 1600w, /img/1790608335521-pasted-image.png 1693w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt="Unreal Engine Blueprint from a MECCHA CHAMELEON Workshop map that writes a batch file to disk"
          
          width="1693" height="1009"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<h2 id="how-did-attackers-take-over-the-official-discord-server">How did attackers take over the official Discord server?</h2>
<p>Attackers took over the official MECCHA CHAMELEON Discord by compromising a spare test machine that a system engineer was using to investigate the malware. From that foothold, they bypassed 2FA on an administrator&rsquo;s Discord account, changed server permissions and banned official staff members (<a href="https://www.notebookcheck.net/Meccha-Chameleon-Workshop-malware-led-to-Discord-server-hijack-RAT-infections.1355649.0.html" target="_blank" rel="noopener noreferrer nofollow">Notebookcheck</a>).</p>
<p>The server has nearly 100,000 members, and access was later restored. Public reports do not explain how the 2FA was bypassed. The development team said the game&rsquo;s source code and production systems were not compromised.</p>
<h2 id="why-does-a-hijacked-official-channel-matter-for-a-brand">Why does a hijacked official channel matter for a brand?</h2>
<p>An official community server is a brand-owned channel: members trust its announcements because they come from the brand. Whoever controls an admin account there can post announcements, decide who can speak and remove the moderators who would normally flag abuse. In the MECCHA CHAMELEON case, attackers used admin access to change permissions and ban official staff.</p>
<p>The pattern goes beyond one game. In June 2026, malicious Wallpaper Engine application wallpapers on Steam Workshop delivered several types of malware (<a href="https://www.scworld.com/brief/malicious-steam-workshop-map-delivered-malware-to-meccha-chameleon-players" target="_blank" rel="noopener noreferrer nofollow">SC Media</a>). Both incidents abuse a channel users already trust, the same logic behind browser extension hijacks and other supply chain attacks.</p>
<p>When the trusted channel belongs to the brand, the damage lands on the brand&rsquo;s reputation even if its core infrastructure was never breached. The same risk applies to hijacked brand accounts on X, Telegram or Instagram, covered in PhishFort&rsquo;s guide to social media impersonation and in a verified account takeover case. A Threat Analyst at PhishFort said:</p>
<blockquote>
<p>The Workshop map was only the entry point. The real damage started when attackers reached an admin account on the official Discord, because from that moment they could speak in the brand&rsquo;s voice to nearly 100,000 people. Studios should protect their community channels with the same care as their login pages.</p></blockquote>
<h2 id="what-should-players-and-it-teams-check">What should players and IT teams check?</h2>
<p>Indicators below are as of September 28, 2026. The sources reviewed did not publish command-and-control domains, so there is nothing to defang.</p>
<table>
  <thead>
      <tr>
          <th>Indicator</th>
          <th>Where to look</th>
          <th>Why it matters</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Workshop maps named Laser Tag Neon or Chroma Grid Arena</td>
          <td>Steam Workshop subscriptions and download history</td>
          <td>Both carried the malicious Blueprint and have been removed</td>
      </tr>
      <tr>
          <td><code>s.bat</code></td>
          <td><code>%USERPROFILE%\Documents</code></td>
          <td>The first-stage file the map dropped</td>
      </tr>
      <tr>
          <td>Unauthorized .bat files</td>
          <td><code>%TEMP%</code></td>
          <td>Possible leftovers of the download chain</td>
      </tr>
      <tr>
          <td>Unknown scheduled tasks or startup entries</td>
          <td>Task Scheduler and Startup apps</td>
          <td>Where a persistent RAT survives restarts</td>
      </tr>
      <tr>
          <td>Game version below 3.1.0</td>
          <td>Steam library, game properties</td>
          <td>Earlier versions let Workshop maps launch external processes</td>
      </tr>
  </tbody>
</table>
<h2 id="how-should-players-studios-and-security-teams-respond">How should players, studios and security teams respond?</h2>
<h3 id="players">Players</h3>
<ol>
<li>Update MECCHA CHAMELEON to version 3.1.0 or later, which blocks Workshop maps from launching external processes.</li>
<li>If you loaded custom maps before updating, run a full antivirus scan.</li>
<li>Check the locations in the indicators table and remove any unauthorized files or startup entries.</li>
<li>Change passwords for accounts used on that PC and sign out other active sessions, since a RAT can capture what happens on the machine.</li>
</ol>
<h3 id="game-studios-and-community-managers">Game studios and community managers</h3>
<ol>
<li>Treat user-generated content as code. Block maps and mods from launching external processes, the fix MECCHA CHAMELEON shipped in 3.1.0.</li>
<li>Investigate suspected malware only on isolated machines that are never signed in to admin accounts for Discord, Steam, or social channels.</li>
<li>Keep a recovery path for official community accounts: backup admins, platform escalation contacts, and a way to warn members through a second channel.</li>
<li>Monitor for impersonation of the brand during and after an incident, when members are least sure which channel is real.</li>
</ol>
<h3 id="corporate-security-teams">Corporate security teams</h3>
<ol>
<li>Keep games and mods off corporate devices, including Bring Your Own Device (BYOD) machines used for work. One infected test machine was enough to reach an admin account in this incident.</li>
<li>Alert on PowerShell launched with an execution-policy bypass by a game or launcher process.</li>
</ol>
<p>PhishFort Brand Protection detects accounts, pages, and domains impersonating a brand across the web, social platforms, and app stores, and handles the takedown. See how it works for game studios and publishers.</p>
<h2 id="are-the-august-2026-windows-11-game-crashes-related">Are the August 2026 Windows 11 game crashes related?</h2>
<p>No. The game crashes some Windows 11 users saw in August 2026 are a separate issue. After the August 11, 2026 security update KB5121003 for Windows 11 versions 24H2 and 25H2, Microsoft received reports that ARC Raiders, MARVEL Tōkon: Fighting Souls and THE FINALS froze, closed without notice, showed an <code>EXCEPTION_ACCESS_VIOLATION</code> error or restarted the device (<a href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/08/kb5121003-windows-11-24h2-25h2-security-update" target="_blank" rel="noopener noreferrer nofollow">Microsoft</a>).</p>
<p>Microsoft associates the problem with RGB lighting peripherals or components that install drivers named like <code>inpoutx64</code>. It resolved the issue with a block that stops the <code>inpoutx64</code> driver from loading, delivered automatically to consumer and unmanaged business devices. Enterprise-managed devices do not get the block automatically, so IT administrators apply the workaround published on the Windows release health site.</p>
<h2 id="faqs">FAQs</h2>







<div class="faq-plain">
  













<p class="faq-plain__q"><strong>Can a Steam Workshop map contain malware?</strong></p>
<div class="faq-plain__a pf-prose">
  Yes, if the game lets map content execute code. In MECCHA CHAMELEON, a hidden Blueprint in a map wrote and ran a batch script that installed a RAT. The risk depends on how each game loads community content, not on Steam Workshop alone.
</div>















<p class="faq-plain__q"><strong>Is MECCHA CHAMELEON safe to play now?</strong></p>
<div class="faq-plain__a pf-prose">
  Version 3.1.0 patched the vulnerability and prevents Workshop maps from launching external processes, and Steam removed the flagged maps. Players should update and stay cautious with maps from unknown uploaders, because new malicious uploads remain possible.
</div>















<p class="faq-plain__q"><strong>What is a Remote Access Trojan (RAT)?</strong></p>
<div class="faq-plain__a pf-prose">
  A Remote Access Trojan is malware that gives an attacker remote control of an infected computer. In the MECCHA CHAMELEON campaign, the RAT was persistent, so it kept running after restarts until removed.
</div>















<p class="faq-plain__q"><strong>How did attackers get into the MECCHA CHAMELEON Discord?</strong></p>
<div class="faq-plain__a pf-prose">
  They compromised a spare test machine an engineer used to investigate the malware, then bypassed 2FA on an administrator&rsquo;s Discord account. With admin access, they changed permissions and banned official staff, and the server was later restored.
</div>















<p class="faq-plain__q"><strong>Should employees play games or install mods on work computers?</strong></p>
<div class="faq-plain__a pf-prose">
  No. Games and mods add code the security team does not control, and a single infected machine can expose every account signed in on it. The rule applies to BYOD devices used for work too.
</div>



</div>


<h2 id="sources">Sources</h2>
<ul>
<li>Feint, <a href="https://medium.com/@FeintBE/workshop-map-for-meccha-chameleon-is-a-malware-dropper-full-breakdown-d1ac29565265" target="_blank" rel="noopener noreferrer nofollow">Workshop map for MECCHA CHAMELEON is a malware dropper (full breakdown)</a>, Medium, July 2026</li>
<li>Darryl Linington, <a href="https://www.notebookcheck.net/Meccha-Chameleon-Workshop-malware-led-to-Discord-server-hijack-RAT-infections.1355649.0.html" target="_blank" rel="noopener noreferrer nofollow">Meccha Chameleon Workshop malware led to Discord server hijack, RAT infections</a>, Notebookcheck, July 30, 2026</li>
<li><a href="https://www.scworld.com/brief/malicious-steam-workshop-map-delivered-malware-to-meccha-chameleon-players" target="_blank" rel="noopener noreferrer nofollow">Malicious Steam workshop map delivered malware to MECCHA CHAMELEON players</a>, SC Media, July 28, 2026</li>
<li>Microsoft, <a href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/08/kb5121003-windows-11-24h2-25h2-security-update" target="_blank" rel="noopener noreferrer nofollow">August 11, 2026: KB5121003 (OS Builds 26200.9168 and 26100.9168)</a>, Microsoft Support</li>
</ul>
]]></content:encoded><category>News</category><category>phishing</category><category>security</category><category>discord</category><category>steam</category><category>malware</category></item></channel></rss>