As originally reported on Kotaku, one user reported on Medium that they and their friends noted that a custom map for the game had a malware dropper within it.
“A couple of my friends reported seeing a command prompt window briefly appear while Steam was downloading a custom workshop map … What I found was a seemingly ordinary workshop map that contained what appears to be a malware dropper, despite having passed workshop review,” said user Feint.
The blog post discussed a map called “Laser Tag Neon”, which causes malware to be executed when the map is launched.
While the map has since been removed, Feint warned that a new malicious map called “Chroma Grid Arena” had been uploaded.
“Only download popular Workshop maps with an established player base,” Feint said.
“If the uploader is a brand-new Steam account or has disabled comments on their Workshop item, consider that a major red flag.
“The malware is executed when you start the match, not when you subscribe to the map. If you only subscribed to a malicious map but never launched it, you can safely unsubscribe.”
Feint also warned Meccha Chameleon players who think or know that they played the maps to check their “%USERPROFILE%\Documents\” and “%TEMP%/” files in their directory, and run a malware scan.
“It’s also a good idea to review your Startup entries and Task Scheduler for anything unfamiliar, as malware commonly uses these mechanisms for persistence.”
The game’s developer confirmed on X that its latest update 3.1.0 fixed the vulnerability, and that malware was disabled for both maps.
However, users confirmed that the official Meccha Chameleon Discord had also been hacked.
The game’s developers in a Steam blog post confirmed that the Discord server, which has almost 100,000 users, has been hacked.
“Currently, the official MECCHA CHAMELEON Discord server has been hacked, and we are completely unable to take any action on our end,” the post said.
“We have already contacted Discord Support and are currently awaiting their response. If the server cannot be recovered, we will set up a new one.”
The threat actors behind the hacks are currently unknown.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.