Steam Workshop malware exploited MECCHA CHAMELEON flaw to infect players

A malicious Steam Workshop map for the game 'MECCHA CHAMELEON' was used to exploit a vulnerability and install a Remote Access Trojan on players' computers. The developers have since patched the flaw, but the incident highlights ongoing security risks in user-generated content platforms.
Why it matters
The incident underscores the cybersecurity risks inherent in modding ecosystems, where malicious actors can bypass standard security checks to compromise end-user systems.
X LinkedIn Reddit Facebook Share A malicious Steam Workshop map for the indie game MECCHA CHAMELEON abused a vulnerability in the game's mod-loading system to execute malware on players' PCs.
Following public disclosure, the developers released an update that fixes the issue, and Steam has removed the known malicious maps, although similar uploads continue to appear.
The campaign was documented by independent reverse engineer Feint, who began investigating after multiple players reported a Command Prompt window briefly flashing while a Workshop map was loading. An analysis of the map , originally published on July 23 and updated several times on July 25, traced the behavior to a malicious Unreal Engine Blueprint hidden inside the Workshop content.
MECCHA CHAMELEON is a multiplayer game built on Unreal Engine 5 that supports user-created maps through the Steam Workshop.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in