TechBeetle | Hackers used Steam Workshop maps to spread malware in Meccha Chameleon, how to stay safe
Tech Beetle briefing IN AI

Hackers used Steam Workshop maps to spread malware in Meccha Chameleon, how to stay safe

Essential brief

Researchers discovered that some custom maps in Meccha Chameleon's Steam Workshop were used to distribute malware, prompting the removal of affected maps and a security update from developers. The

Key topics

hackers used steam workshop maps hackers used steam workshop maps spread malware meccha chameleon stay safe Researchers Steam Workshop

Key facts

Malicious maps in Meccha Chameleon's Steam Workshop were used to distribute Remote Access Trojan malware.
Affected maps have been removed and a security update (version 3.1.0) was released to fix the vulnerability.
The malware compromised an administrator's Discord account and the official game server.
Players should verify Workshop content sources, scan for malware, and update the game promptly.

Highlights

Two malicious maps, Laser Tag Neon and Chroma Grid Arena, were removed from Steam Workshop.
Malware created batch files and used PowerShell to download and install a RAT.
The game itself was never infected; the issue was limited to a testing PC and compromised Discord account.
Developers released version 3.1.0 to prevent malicious Workshop maps from executing scripts.
Players are advised to check for suspicious files and only download maps from trusted creators.

Why it matters

This incident underscores the security risks posed by user-generated content on digital distribution platforms like Steam. Malicious actors can exploit community-created maps to deliver malware, compromising both players and developers' infrastructure. Ensuring robust content moderation and timely security updates is essential to protect users and maintain trust in online gaming ecosystems.

Steam users playing Meccha Chameleon with custom maps from the Steam Workshop have been exposed to malware through certain community-created maps. Players first noticed suspicious behavior when a Command Prompt window briefly appeared while loading specific maps. Further investigation revealed that one malicious map created a batch file in the player's Windows Documents folder and attempted to download an additional script from an external server. This script was later found to install a Remote Access Trojan (RAT), enabling attackers to remotely control infected systems.

The two identified malicious maps, Laser Tag Neon and Chroma Grid Arena, have been removed from the Steam Workshop following the discovery. The malware operated by creating a batch file that launched PowerShell in the background to fetch the secondary script. Although the initial download returned a 404 error, subsequent analysis confirmed the script's purpose was to install the RAT.

Developers of Meccha Chameleon have confirmed that the game itself was never compromised. The infection was limited to a testing PC used during the investigation of the malicious Workshop content. However, the malware also allowed attackers to hijack an administrator's Discord account, bypass two-factor authentication, and take control of the game's official Discord server. The compromised computer has since been wiped, and players have been warned to disregard any suspicious announcements or links from the affected Discord server.

To address the vulnerability, the developers released version 3.1.0 of Meccha Chameleon, which prevents malicious Workshop maps from executing harmful scripts. Players who have only subscribed to malicious maps but have not launched them are not believed to be at risk. Those who played affected maps before updating should take precautions by checking for unfamiliar batch files in their Documents and Temp folders, reviewing startup items and scheduled tasks for unknown entries, and running a full malware scan with trusted security software.

Users are advised to download Workshop maps only from creators with active community feedback and to avoid new accounts or listings with disabled comments. Staying vigilant and applying updates promptly can help mitigate risks associated with community-generated content on Steam.

Key topics in this update include hackers used steam workshop maps, hackers used steam, and workshop maps.