Independent researcher Feint discovered malicious Steam Workshop maps ('Laser Tag Neon' and 'Chroma Grid Arena') were dropping a Remote Access Trojan (RAT) on players' PCs in late July 2026. Players who launched the infected maps were vulnerable: the malware executed when loading a match, wrote a .bat file to Docume...

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What happened in the Meccha Chameleon malware and Discord hijacking incident, how did custom maps. Article summary: Here is a complete, sourced breakdown of the incident.. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
In late July 2026, the indie hit Meccha Chameleon became the target of a two-stage cyberattack that exposed a critical vulnerability in Steam Workshop's user-generated content pipeline. Hackers first embedded a Remote Access Trojan (RAT) inside custom maps, then used an infected developer machine to hijack the game's official Discord server with over 100,000 members . The developers patched the game vulnerability in version 3.1.0 and regained control of the server within days
. Here is everything that happened and what players need to know to stay safe.
The attack chain began on July 24, 2026, when independent security researcher Feint (FeintBe) discovered that several user-created maps on the Steam Workshop were hiding malware . The known infected maps were "Laser Tag Neon" and "Chroma Grid Arena"
.
When a player loaded one of these infected maps, a hidden script wrote a .bat file to the user's Documents folder and used PowerShell to fetch additional malicious payloads from a remote server . That payload was a Remote Access Trojan (RAT) — malware that gave attackers full remote control over the victim's PC
.
Crucially, the malware executed only when a player launched the map in-game. Simply subscribing to the map on Steam Workshop without loading it did not trigger the infection . The maps exploited a vulnerability in how the game processed user-generated content, allowing arbitrary code execution on the player's machine
.
The 100,000-member Discord server hijacking was a direct consequence of the malware infection, not a separate attack.
While investigating the malicious maps, the developers — Lemorion_1224 and Haganeiro — downloaded the infected content onto a systems engineer's testing PC to analyze the threat. That machine became compromised . The attacker used this foothold to steal an administrator account's credentials and bypassed two-factor authentication (2FA) by hijacking an active Discord session
. Once inside, the attacker banned all existing admins, locked out the development team, and seized full control of the server
. The hackers then posted fake messages urging players to "delete the game immediately" and spread more malware links from the compromised server
. Developer Lemorion_1224 stated publicly: "Security was completely breached, the server creator's account was hijacked, and all admins were banned, so we can't take action from our side"
.
The development team moved quickly on several fronts:
Developer Haganeiro confirmed that the vulnerability was fully fixed in update 3.1.0 and that the malware in the affected maps had been disabled .
Version 3.1.0 contains the fix. Players still on older versions remain vulnerable .
During the hijack, hackers posted fake "delete the game" warnings and malicious links. After the server was reclaimed, all such posts were removed, but any player who interacted with them should be cautious .
Any player who downloaded and launched "Laser Tag Neon" or "Chroma Grid Arena" after mid-July 2026 should run a full antivirus or anti-malware scan immediately. Security researcher Feint warned that the malware could give attackers full remote access to the victim's PC .
Feint specifically warned: "If the uploader is a brand-new Steam account or has disabled comments on their Workshop item, consider that a major red flag" .
The exploit was in the custom content pipeline, not in the base game files. The developers confirmed that even if a hacker compromised a developer PC, Steam's infrastructure prevents unauthorized game updates from being published .
If you suspect your PC was compromised, run a full malware scan with a trusted anti-malware tool such as MalwareBytes. In severe cases, a full Windows reinstallation may be the safest option .
The Meccha Chameleon Steam Workshop malware and Discord hijack serves as a reminder that user-generated content can be a vector for serious security threats, even on platforms with review processes. The developers have patched the exploit, removed the known malicious maps, and reclaimed their community server. Players should update to version 3.1.0, run a malware scan if they played custom maps, and exercise caution when downloading user-generated content from unknown creators in the future .
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Independent researcher Feint discovered malicious Steam Workshop maps ('Laser Tag Neon' and 'Chroma Grid Arena') were dropping a Remote Access Trojan (RAT) on players' PCs in late July 2026.
Independent researcher Feint discovered malicious Steam Workshop maps ('Laser Tag Neon' and 'Chroma Grid Arena') were dropping a Remote Access Trojan (RAT) on players' PCs in late July 2026. Players who launched the infected maps were vulnerable: the malware executed when loading a match, wrote a .bat file to Documents, and used PowerShell to fetch a RAT.
The exploit has been patched in version 3.1.0+. Players should update the game, avoid custom maps from unknown or brand new Steam accounts, run a malware scan if they played 'Laser Tag Neon' or 'Chroma Grid Arena', an...