Custom maps for the indie hit Meccha Chameleon distributed through the Steam Workshop were exploited in an attempt to install malware on players’ computers.
The security breach came to light following an independent investigation that identified suspicious command-line instructions hidden inside community-created scenarios.
Developers confirmed the vulnerability and released patch 3.1.0 to block further exploitation. The core security flaw did not stem from official game files but rather from the system responsible for loading modified maps downloaded via Valve’s platform.
Cybersecurity researcher Feint discovered the suspicious behavior within a workshop map titled Laser Tag Neon. Loading the custom scenario under Windows triggered a brief Command Prompt window.
Further analysis revealed malicious logic embedded in Unreal Engine Blueprints. The code generated an s.bat file within the Documents folder and spawned a hidden PowerShell process to download secondary scripts from a remote server.
‼️ Steam is hosting malware again, this time in a custom map for the game MECCHA CHAMELEON
Loading the map quietly writes a Windows command file into the player’s Documents folder, which then opens PowerShell in an invisible window and tries to download a second script from a… pic.twitter.com/96oK7T8Xxx
— International Cyber Digest (@IntCyberDigest) July 25, 2026
Although the attacker’s server returned a 404 error during the investigation—preventing analysts from identifying the final payload—the code served no legitimate function within game maps. Laser Tag Neon was subsequently removed, though reports indicate additional malicious scenarios were uploaded shortly after. The exploit activated upon executing the map or joining a lobby running the infected scenario.
The development team addressed the exploit in version 3.1.0, neutralizing malicious content across older versions as well. Users who accessed Laser Tag Neon are advised to unsubscribe, run a full system scan, and check for s.bat files without opening them manually.
During the investigation, a developer executed the infected map on a secondary computer, leading to compromised credentials and an unauthorized takeover of the official Discord server. The attacker banned team members and posted false claims alleging that update 3.1.0 contained a trojan, which developers firmly denied. The affected machine was formatted, and developers confirmed it held no access to official build distribution files.
Launched in June, Meccha Chameleon has emerged as one of 2026’s largest indie successes, surpassing 15 million copies sold in under a month.
Filed in . Read more about Exploit, Game, Gaming, Malware and Security.

