Software & SaaS

Meccha Chameleon Steam Workshop Maps Delivering Malware

Malicious scripts are reportedly being delivered via custom maps for the popular indie game Meccha Chameleon on Steam. Users are advised to scan PCs for malware.

Christopher Clark
Christopher Clark covers software & saas for Techawave.
2 min read0 views
Meccha Chameleon Steam Workshop Maps Delivering Malware
Share

A serious security concern has emerged around the highly popular indie game Meccha Chameleon, with reports indicating that certain custom maps available on the Steam Workshop may be distributing malware. A security researcher identified a malicious script embedded within a user-created map designed to infect players' PCs.

The issue was first flagged by a researcher known as Feint, who detailed their findings on Medium.com. Feint observed a command prompt window briefly appearing when Steam downloaded a custom map for Meccha Chameleon. While the map's files initially appeared normal, deeper analysis revealed a hidden Blueprint actor within the map's metadata. This actor is designed to execute automatically upon map loading.

According to Feint's investigation, the embedded script injects a batch file into the user's Documents folder. This batch file then initiates a hidden PowerShell process, bypassing execution policies, to connect to an external server and download a secondary script. While Feint's tests prevented the full download of the secondary script, thus leaving its ultimate purpose unclear, the act of writing and executing external scripts from a game map is a clear indicator of malicious intent.

The Steam account responsible for uploading the suspect map has also raised red flags. It was reportedly only a week old and had comments and ratings disabled, making it difficult for other users to share warnings or feedback. The map has since been reported to Steam, though no specific actions have been publicly confirmed by Valve.

Developer Statements and Mitigation Steps

In response to the findings, the developers of Meccha Chameleon issued a statement clarifying that the game itself is safe and virus-free. They stated that the incident was linked to a compromised Discord admin account, not the game's core files. The compromised PC was a spare testing machine, isolated from the game's source code. The affected system has been wiped and reformatted. The developers also warned players against trusting any further communications or links from the compromised Discord server, anticipating potential fake statements from the perpetrator.

For players who have downloaded custom maps for Meccha Chameleon, it is strongly recommended to exercise caution. Until Valve addresses the issue by removing malicious content from the Steam Workshop, users should avoid downloading new custom maps, especially those with disabled comments or a lack of reviews. Additionally, running a comprehensive PC scan with antivirus software is advised. Players can also manually check their Documents folder for any unusual `.bat` files.

This incident highlights a recurring challenge for platforms like Steam, where user-generated content can be exploited. Although Steam's Workshop aims to provide a rich ecosystem for game modifications, it remains vulnerable to screening process oversights. This situation echoes a similar incident involving Wallpaper Engine last month, where malware was discovered within the popular PC background application, underscoring the ongoing need for vigilance from both platform holders and users.

Share