Meccha Chameleon players have found themselves in the crosshairs of a sophisticated cyberattack after malicious Steam Workshop maps infected devices and led to the official Discord server being taken over. The attack has resulted in infected PCs and a compromised developer account.
The exploit was discovered by independent researcher Feint, who found that some custom maps such as Laser Tag Neon contained code that wrote a batch file to a player's Documents folder. From here, the file then attempted to use PowerShell to download additional malware and remote access trojans.
Developer Haganeiro confirmed the vulnerability was patched in update 3.1.0, but warned users to scan their systems and avoid the original Discord server. The map has since been removed, and the malware has been disabled for players who haven't installed the update.
Infected Maps
- Laser Tag Neon
- Chroma Grid Arena
The breach severity was turned up a notch when a system engineer's PC that was used to investigate the infected maps became compromised. The attackers bypassed two-factor authentication on Discord, altered permissions, and banned staff members. False claims about the official build being malicious were spread through the hijacked server.
"The vulnerability in the custom maps described in today's update 3.1.0 has been fixed, so there are no issues after applying it," said Haganeiro
A replacement Discord server is being set up, and the official Steam version of Meccha Chameleon is considered safe. Players who used the malicious maps before the patch are urged to check their Documents and temp folders for suspicious .bat files, run a full system scan, or, just to be safe, completely reinstall your operating system.

Frequently Asked Questions
TweakBot answers common questions about this news using TweakTown's own coverage from this page and related content from our archive. Tap a question to reveal the answer, or type your own below.
Which game update patched the vulnerability and is the official Steam build now safe?
What immediate steps should I take to check if my PC was infected (which folders and file types to look for)?
Could the malware bypass Discord two-factor authentication and how did it affect the official Discord server?
If I used one of the infected maps before the patch, what cleanup options are recommended (scan vs. full OS reinstall)?
Have a question not listed here? Ask below and TweakBot will answer it.
What is good to know is that the research said subscribing to the map wasn't enough to infect your PC; you are only at risk of infection if you actually opened and launched into a match on one of these maps.






