Meccha Chameleon was hit by a two-part security incident after a Steam Workshop custom map that had already passed review was found to contain a malware dropper, and the game’s official Discord server, with close to 100,000 members, was later taken over by attackers for a period of time.
Workshop map carried a suspected malware dropper
Security researcher Feint said in a Medium post that the issue came to light after several friends noticed a command prompt window briefly appear while downloading a custom Workshop map on Steam. After looking into it, Feint wrote that the map appeared normal and had already passed Workshop review, but contained what looked like a malware dropper.
The map identified in the incident was Laser Tag Neon. In a later update, Feint said another map called Chroma Grid Arena had been uploaded as a replacement, expanding the infection risk.
According to technical analysis cited from cybernews, the malicious map writes a .bat file into the user’s Documents folder and then uses PowerShell to download follow-on code.
The trigger condition was specific: players had to actually launch the affected map for the infection to run. Merely subscribing to the Workshop item did not infect a machine.
Haganeiro says update 3.1.0 fixed the vulnerability
Haganeiro confirmed the issue on X on Saturday and said the problem had been fixed. The developer wrote: “The vulnerability in custom maps described in today’s 3.1.0 update has been fixed, so there will be no issue after applying the update. We have also confirmed that the malware in the affected maps has been disabled both before and after the update.”
The post carried the date July 25, 2026.
Official Discord server was also compromised
At the same time, the game’s official Discord server, which had close to 100,000 members, was compromised. Developer lemorion_1224 said on X that a systems engineer’s computer became infected with malware during work to patch the vulnerability tied to the custom maps.
According to that explanation, the attacker bypassed two-factor authentication on the engineer’s Discord account, changed server permissions and locked out all staff members.
In a Steam community notice, the developer said it had contacted Discord support and was waiting for a response. If the server could not be recovered, the team said it would create a new one.
Server has been restored
The official Discord server has now been fully restored. The accounts involved in the incident have been banned, and the developer has issued a new invite link for players who want to return.
lemorion_1224 also warned players not to click any “suspicious links” posted in Discord during the compromise. The affected engineer’s machine was described as a backup computer that has since been wiped. It was not able to edit game files, and the developer said the intrusion did not spread into official distribution channels.
For players who launched the malicious map before the fix, the report recommended checking the Documents folder and temporary directories for suspicious .bat files, running a full antivirus scan, and reinstalling the operating system if necessary.

