

The Meccha Chameleon development team has confirmed that the game’s Steam Workshop has been exploited by malicious actors. Malicious maps have been exploiting the game’s mod-loading system to execute code outside of the game, a weakness that required an immediate fix. The discovery prompted an emergency security response from the game’s development team, with an update to cover the weakness being quickly released. The Steam Workshop incident also coincided with the development team’s official Discord server being compromised, with statements for the team suggesting a connect exists between both incidents.
Looking at an analysis of the malware that infected certain Steam Workshop maps for Meccha Chameleon, the malicious software executed Windows scripts to retrieve a currently unknown payload. Being more specific, the maps contained Unreal Engine Blueprint logic that created a batch file in the user’s Documents folder. This batch file would then launch a hidden PowerShell process in an attempt to retrieve an additional payload from a remote server. The analysis could not determine what the final payload was because testing of this PowerShell process would always fail during this second-stage download: it would only return a 404 response. While researchers understand how the dropper operates, we have no confirmation as to what the final malware payload would have done to a potential victim.
According to an official Steam announcement, Meccha Chameleon‘s developers have already released an update that blocks malware attacks of this nature by preventing Workshop maps from performing this behavior. This does mean that the game has been patched to address the this specific exploit of Meccha Chameleon‘s code. In a separate announcement, the developers announced that their official Discord server had been hacked, causing them to lose administrative control temporarily and advising players not to trust any messages posted on the server until administrative control was restored.
《めっちゃカメレオン》
公式discordサーバーハッキングについて全貌が発覚しましたのでお伝えします。
✅結論から言うとゲーム本体にウイルスは100%ありません。
discordの管理者のアカウントが乗っ取られたという一点だけです。…— LEMORION🌌レモリオン (@lemorion1224) July 25, 2026
While these were initially believed to be separate incidents, other developer statements indicate that a connection between the two exists. Investigations by the development team suggest that team members were infected by the dropper malware while analyzing the malicious Workshop content. This suggests that the infection could have allowed attackers to compromise administrator accounts and gain control of the official Discord server.
