TechNewsReel
Live

Meccha Chameleon Hackers Seize 100K-User Discord via Malicious Steam Maps

A vulnerability in custom map loading let attackers distribute malware, bypass 2FA, and seize control of the game's official community server before developers patched the exploit.

TechNewsReel Newsroom · July 27, 2026

Hackers exploited a security vulnerability in Meccha Chameleon to distribute malware through Steam Workshop maps, ultimately hijacking the game's official Discord server and its nearly 100,000 members.

The attack vector was deceptively simple: malicious custom maps titled 'Laser Tag Neon' and 'Chroma Grid Arena' contained embedded malware disguised as normal Unreal Engine Blueprints. When players downloaded and launched these maps, the code wrote a batch file to the user's Documents folder and spawned a hidden PowerShell process to fetch additional payloads.

From Infected PCs to Discord Takeover

The compromise escalated beyond individual infections. According to multiple outlets including PC Gamer and Dexerto, the malware bypassed two-factor authentication on a single system engineer's Discord account. This gave attackers administrative permissions to ban official staff members and seize control of the server.

Developer Haganeiro confirmed that no official game files, source code, or Steam developer accounts were compromised—only the one engineer's PC and Discord credentials were breached.

Patch Deployed, Hackers Banned

Within hours of the discovery going public, the two-person development team (Haganeiro and Lemorion_1224) released update 3.1.0 to patch the vulnerability. The studio also banned the malicious actors and regained control of the Discord server.

"The vulnerability in the custom maps described in today's update 3.1.0 has been fixed, so there are no issues after applying it," Haganeiro said in a statement covered by PC Gamer.

A Warning for User-Generated Content

The incident underscores the security risks inherent in platforms that allow community-created content. Meccha Chameleon's Steam Workshop integration—meant to extend the game's lifespan through player-made maps—became an attack surface that endangered both end users and the developers' own infrastructure.

Unlike typical modding scandals where rogue content merely breaks gameplay, this exploit demonstrated how a map-loading vulnerability can chain into privilege escalation, credential theft, and mass community platform compromise. Players who installed update 3.1.0 are protected, but the breach serves as a stark reminder that user-generated content requires rigorous sandboxing and code review.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.