Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: Win an ADATA SE880 2TB Portable External SSD

Steam Workshop maps infected players with malware and took over a 100,000-member Discord

Meccha Chameleon Discord hacked via malicious Steam maps, developer patches exploit, warns players to do full system scans immediately.

Steam Workshop maps infected players with malware and took over a 100,000-member Discord
Comments
Tech and Science Editor
Published
1 minute & 15 seconds read time
TL;DR: Malicious Steam Workshop maps (Laser Tag Neon, Chroma Grid Arena) infected Meccha Chameleon players by writing a .bat to Documents and using PowerShell to fetch malware, compromising developer systems and the official Discord. Researcher Feint identified it; developer Haganeiro patched it in update 3.1.0, removed the map, and urges scans or full reinstalls for affected users. Infection required launching the maps, not merely subscribing.
Voice: Jak Connor
0:00 / 2:24
Use left and right arrow keys to seek audio.

Meccha Chameleon players have found themselves in the crosshairs of a sophisticated cyberattack after malicious Steam Workshop maps infected devices and led to the official Discord server being taken over. The attack has resulted in infected PCs and a compromised developer account.

The exploit was discovered by independent researcher Feint, who found that some custom maps such as Laser Tag Neon contained code that wrote a batch file to a player's Documents folder. From here, the file then attempted to use PowerShell to download additional malware and remote access trojans.

Developer Haganeiro confirmed the vulnerability was patched in update 3.1.0, but warned users to scan their systems and avoid the original Discord server. The map has since been removed, and the malware has been disabled for players who haven't installed the update.

Infected Maps

  • Laser Tag Neon
  • Chroma Grid Arena

The breach severity was turned up a notch when a system engineer's PC that was used to investigate the infected maps became compromised. The attackers bypassed two-factor authentication on Discord, altered permissions, and banned staff members. False claims about the official build being malicious were spread through the hijacked server.

"The vulnerability in the custom maps described in today's update 3.1.0 has been fixed, so there are no issues after applying it," said Haganeiro

A replacement Discord server is being set up, and the official Steam version of Meccha Chameleon is considered safe. Players who used the malicious maps before the patch are urged to check their Documents and temp folders for suspicious .bat files, run a full system scan, or, just to be safe, completely reinstall your operating system.

Frequently Asked Questions

TweakBot answers common questions about this news using TweakTown's own coverage from this page and related content from our archive. Tap a question to reveal the answer, or type your own below.

Question #1

Which game update patched the vulnerability and is the official Steam build now safe?

The vulnerability was patched in update 3.1.0. The article states the official Steam version of Meccha Chameleon is considered safe after that update.
Answered
Question #2

What immediate steps should I take to check if my PC was infected (which folders and file types to look for)?

Check your Documents and temp folders for suspicious .bat files, since the malicious maps wrote a batch file to Documents and then used PowerShell to download additional malware. Run a full system scan immediately, and if you want maximum safety consider completely reinstalling your operating system.
Answered
Question #3

Could the malware bypass Discord two-factor authentication and how did it affect the official Discord server?

Yes. The attackers bypassed Discord two-factor authentication on a compromised system engineer's PC, which allowed them to take over the official Discord server. They altered permissions, banned staff members, and used the hijacked server to spread false claims that the official build was malicious.
Answered
Question #4

If I used one of the infected maps before the patch, what cleanup options are recommended (scan vs. full OS reinstall)?

The article urges players who used the malicious maps before the patch to check their Documents and temp folders for suspicious .bat files and to run a full system scan. It also says, just to be safe, you can completely reinstall your operating system.
Answered

Have a question not listed here? Ask below and TweakBot will answer it.

What is good to know is that the research said subscribing to the map wasn't enough to infect your PC; you are only at risk of infection if you actually opened and launched into a match on one of these maps.

Photo of the Paintable Meccha Chameleon DIY Kit

Best Deals: Paintable Meccha Chameleon DIY Kit

Prices last scanned 2 hours and 8 minutes ago

* Prices may be inaccurate. As an Amazon Associate, we earn from qualifying purchases. We earn affiliate commission from any Newegg or PCCG sales.

News Source:dexerto.com

Comments

Tech and Science Editor

Email IconX IconLinkedIn Icon

Jak joined TweakTown in 2017 and has since reviewed 100s of new tech products and kept us informed daily on the latest science, space, and artificial intelligence news. Jak's love for science, space, and technology, and, more specifically, PC gaming, began at 10 years old. It was the day his dad showed him how to play Age of Empires on an old Compaq PC. Ever since that day, Jak fell in love with games and the progression of the technology industry in all its forms.

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News
Newsletter Subscription