Developers of the popular game Meccha Chameleon faced a large-scale cyberattack that began with the distribution of malware via the Steam Workshop and ended with the complete takeover of the studio's official Discord server. The incident, which gained widespread attention following an investigation by independent cybersecurity expert Feint, demonstrated vulnerabilities in the mod moderation system and led to a loss of control over community communication.

Trojan Map in the Steam Workshop

The first link in the chain of incidents was a custom map named Laser Tag Neon. Although the modification successfully passed moderation in the Steam Workshop, it contained hidden malicious code. As researcher Feint discovered, when the map was launched on a user's computer, the following occurred:

  • The Windows command line opened briefly.
  • A hidden file containing a command was created in the user's "Documents" folder.
  • A PowerShell window launched in the background, initiating the download of a secondary malicious script.

After the report was published, the map was promptly removed from the Workshop. However, the attackers, unwilling to stop, began spreading similar malicious code through other modified maps that players downloaded, unaware of the threat.

Emergency Update and Recommendation for Players

The studio lemorion_1224, behind the creation of Meccha Chameleon, reacted to the threat immediately. An updated patch version v3.1.0 was released, which closed a critical vulnerability in the user modification loading system.

Developers strongly recommend that all players who launched fan-made maps before this update perform a full system scan using antivirus software to rule out the presence of malicious files.

Loss of Control Over the Discord Server

However, eliminating the security hole in the game did not save the studio from a further blow. Immediately after the patch release, an alarming message appeared on the project's official Steam page: the developers had lost control of their official Discord server.

In the studio's statement, it says:

"The game itself was not affected. Currently, the official MECCHA CHAMELEON Discord server is broken, and we are completely unable to take any measures on our side. We have already contacted Discord support and are waiting for a response. If the server cannot be restored, we will create a new one".

How Hackers Bypassed Protection

Subsequently, the developers clarified the details of the hack on the social network X. It turned out that during the attempt to eliminate the vulnerability, the computer of one of the studio's system engineers was infected by the malware.

The attackers managed to:

  • Bypass the two-factor authentication (2FA) system.
  • Change access rights on the server.
  • Block all official employees, depriving them of the ability to manage the community.

At the moment, regaining control of the server is impossible, and the team is forced to wait for a response from Discord support or prepare to create a new communication channel.