Meccha Chameleon, the indie breakout that has already sold over 15 million copies in 2026, confirmed on July 25 that malware was distributed through multiple Steam Workshop community maps and that its official Discord server was separately compromised,
Here’s the context: On July 24, independent security researcher Feint published a report on Medium documenting how a community map called Laser Tag Neon – despite having cleared Steam’s Workshop review process – would briefly flash a command prompt window and begin downloading a script to install malware on Windows PCs. The attack chain, as described by International Cyber Digest on X, involved the map quietly writing a Windows command file into the player’s Documents folder, then opening PowerShell in a hidden window to pull down a second-stage script from an external server. Laser Tag Neon was removed after Feint’s report, but Feint subsequently confirmed that new malicious maps had been uploaded to fill the gap before the underlying vulnerability was closed.

Developer lemorion_1224 confirmed the issue has been patched in today’s version 3.1.0 update. The fix addresses the execution path that allowed Workshop maps to write and run files on a player’s machine in the first place – meaning the malware campaign was exploiting something baked into how the game loaded community content, not just a rogue uploader getting lucky through review.
Honestly, the timing and scale here are about as bad as they get. Meccha Chameleon is the hottest game on Steam right now, which made its Workshop a high-value target the moment it went live. Steam’s automated Workshop review passed Laser Tag Neon – a reminder that Valve’s content scanning is not a security audit, and that a green tick from Workshop review means nothing about whether a map is safe to load. The fact that replacement malicious maps appeared almost immediately after the first was pulled shows the attackers were monitoring the situation in real time and treating the Workshop as an open distribution pipeline until the patch landed.
The Discord situation compounds the damage significantly. According to a statement from lemorion_1224, a system engineer’s PC was infected with malware while the team was actively working to address the Workshop issue – and the attacker used that foothold to bypass the engineer’s two-factor authentication on Discord, escalate permissions inside the server, and ban every staff member. The developer’s statement on Steam confirms the team is in contact with Discord Support but currently has no ability to take any action on the server itself. If Discord cannot recover the original server, lemorion_1224 says they will establish a new one.

and whether the replacement maps that followed the removal of Laser Tag Neon reached a meaningful number of users.
What to watch: Players who downloaded any Meccha Chameleon Workshop maps before the 3.1.0 update should run a scan It is also worth watching whether Valve issues any platform-level guidance or adjusts Workshop permissioning for the game – right now the confirmed fix is the developer’s v3.1.0 patch. Incidents like this one and recent infrastructure disruptions across other platforms are a persistent reminder that player-facing digital infrastructure carries real security exposure,
Have you already updated to version 3.1.0, and did you load any Workshop maps in the days leading up to the patch? Let us know in the comments whether the developer’s communication on this has been adequate given how large the game’s player base already is.























