The attack chain began on July 24, 2026, when independent security researcher Feint (FeintBe) discovered that several user-created maps on the Steam Workshop were hiding malware . The known infected maps were "Laser Tag Neon" and "Chroma Grid Arena" .
When a player loaded one of these infected maps, a hidden script wrote a .bat file to the user's Documents folder and used PowerShell to fetch additional malicious payloads from a remote server . That payload was a Remote Access Trojan (RAT) — malware that gave attackers full remote control over the victim's PC .
Crucially, the malware executed only when a player launched the map in-game. Simply subscribing to the map on Steam Workshop without loading it did not trigger the infection . The maps exploited a vulnerability in how the game processed user-generated content, allowing arbitrary code execution on the player's machine .
The 100,000-member Discord server hijacking was a direct consequence of the malware infection, not a separate attack.
While investigating the malicious maps, the developers — Lemorion_1224 and Haganeiro — downloaded the infected content onto a systems engineer's testing PC to analyze the threat. That machine became compromised . The attacker used this foothold to steal an administrator account's credentials and bypassed two-factor authentication (2FA) by hijacking an active Discord session . Once inside, the attacker banned all existing admins, locked out the development team, and seized full control of the server . The hackers then posted fake messages urging players to "delete the game immediately" and spread more malware links from the compromised server . Developer Lemorion_1224 stated publicly: "Security was completely breached, the server creator's account was hijacked, and all admins were banned, so we can't take action from our side" .
The development team moved quickly on several fronts:
Developer Haganeiro confirmed that the vulnerability was fully fixed in update 3.1.0 and that the malware in the affected maps had been disabled .
Version 3.1.0 contains the fix. Players still on older versions remain vulnerable .
During the hijack, hackers posted fake "delete the game" warnings and malicious links. After the server was reclaimed, all such posts were removed, but any player who interacted with them should be cautious .
Any player who downloaded and launched "Laser Tag Neon" or "Chroma Grid Arena" after mid-July 2026 should run a full antivirus or anti-malware scan immediately. Security researcher Feint warned that the malware could give attackers full remote access to the victim's PC .
Feint specifically warned: "If the uploader is a brand-new Steam account or has disabled comments on their Workshop item, consider that a major red flag" .
The exploit was in the custom content pipeline, not in the base game files. The developers confirmed that even if a hacker compromised a developer PC, Steam's infrastructure prevents unauthorized game updates from being published .
If you suspect your PC was compromised, run a full malware scan with a trusted anti-malware tool such as MalwareBytes. In severe cases, a full Windows reinstallation may be the safest option .
The Meccha Chameleon Steam Workshop malware and Discord hijack serves as a reminder that user-generated content can be a vector for serious security threats, even on platforms with review processes. The developers have patched the exploit, removed the known malicious maps, and reclaimed their community server. Players should update to version 3.1.0, run a malware scan if they played custom maps, and exercise caution when downloading user-generated content from unknown creators in the future .