Meccha Chameleon Patch Fixes Malware Exploit in Steam Workshop Maps; Discord Server Hacked

July 27, 2026
Meccha Chameleon Patch Fixes Malware Exploit in Steam Workshop Maps; Discord Server Hacked
  • A vulnerability in Meccha Chameleon allowed malware to be distributed through Steam Workshop maps, notably the Laser Tag Neon map, with a follow-up map Chroma Grid Arena, and a patch was subsequently released to fix the issue.

  • Developer Haganeiro confirmed the issue was resolved in update 3.1.0, and malware was disabled for affected maps both before and after the patch.

  • Security researchers found that several Steam Workshop maps contained malware dropper payloads hidden inside benign Unreal Engine 5 assets, enabling execution during level load.

  • The Discord incident prompted actions including contacting Discord Support and considering setting up a new Discord server if recovery proves impossible.

  • At the time of reporting, the threat actors behind the hacks remained unidentified, and the incident affected Meccha Chameleon’s Discord community of nearly 100,000 users.

  • Players were urged to be cautious with community content, as a single compromised account with comments disabled can still pose risks, underscoring that platform-level scanning was a missing safeguard.

  • The Discord server compromise led to false announcements about a remote access Trojan and general panic; developers clarified the game itself remained clean and that a compromised PC did not have access to game source files or Steam developer accounts.

  • The official Discord server was hacked, compromising staff permissions and bypassing two-factor authentication on a system engineer’s PC.

  • A system engineer’s backup PC was infected, allowing the attacker to bypass Discord 2FA, take control of the Meccha Chameleon Discord server, alter permissions, and ban staff.

  • The attack also compromised a testing machine used by a system engineer, granting attacker access to an administrator account on the Discord server; developers denied that game updates contained malware.

  • The attacker blocked existing admins, posted a fake update claiming a RAT, and guided users through a recovery process, causing widespread confusion.

  • Despite the security incident, the base game remains well-received as a creative take on hide-and-seek, though players must be vigilant with user-created content.

Summary based on 7 sources


Get a daily email with more Gaming stories

More Stories