MECCHA CHAMELEON's Steam Workshop Is Dropping Malware, and the Dev's Accounts Got Hacked Too
By CriticalPixel ·
The party game that took over Twitch streamers' schedules this summer just became a cautionary tale about Steam Workshop trust. MECCHA CHAMELEON, the hand-drawn hide-and-seek game where you paint your white body to mimic the stage and fool the seekers, is at the center of an active malware incident that has players scrubbing their subscriptions and the developer fighting to reclaim its own accounts. A security researcher reported a malicious Workshop map that drops a malware loader onto players' PCs, and the situation escalated fast from there. If you have touched the game's Workshop content in the past few weeks, this one concerns you directly, and the official channels you would normally trust are part of the problem right now.
What the malicious map actually does
According to the breakdown shared by Pirat Nation and reported by Windows Central, the offending map planted a .bat batch file on a player's machine the moment it loaded. That batch file then attempted to launch PowerShell and pull a second file down from a remote server, a textbook dropper pattern that security researchers see in the wild constantly. The catch is that the second-stage download was offline during testing, so nobody has confirmed what the final payload was meant to deliver, and that uncertainty is what makes the incident so uncomfortable. The map was uploaded under the name 'Laser Tag Neon' before Valve removed it, though some players claim it resurfaced later under a different name. Valve has not confirmed that reappearance or issued any official statement about the incident at all, which leaves players piecing together their own risk assessment from community reports.
The attack did not stop at the Workshop
This is where the story gets uglier than a single bad mod. Reports circulating from players and the community say both of the developer's accounts were compromised, meaning recent posts and updates may not have come from the real team at all. The official MECCHA CHAMELEON Discord server was taken over as well, with the game's own account warning players to avoid it and pointing them toward an unofficial community server instead. One community member summed it up bluntly, telling others to treat the latest update with suspicion because the people posting were not the actual developers and the Discord had already been nuked. The developer has since said that update 3.1.0 addresses the malicious Workshop maps, which is the closest thing to an official fix players have right now, but the broader question of who controlled those accounts during the attack is still unresolved.
Why Steam Workshop keeps getting burned
The reaction under the original report tells you a lot about how much trust the mod ecosystem runs on. Players pointed out that Steam Workshop trains people to hit Subscribe like they are grabbing a cosmetic skin, not installing executable code from a stranger's upload, and that one malicious map is enough to expose how fragile that assumption is. Others noted that malware has been delivered through Steam before, and that the problem is only going to grow as Workshop content spreads to more games and bigger audiences. One technical question kept coming up too: a .bat file is not supposed to run automatically on download, so the game itself may be doing something that launches it. That detail matters, because it decides whether this is a Workshop vetting failure, a game-level vulnerability, or both at once. MECCHA CHAMELEON is also a painfully visible target right now, packed with streamers and VTuber collabs, which is the kind of audience an attacker wants to reach when they plant something like this.
What players should do right now
If you have subscribed to any MECCHA CHAMELEON Workshop maps, the practical advice is simple and worth doing today rather than later. Unsubscribe from any map you do not personally recognize, especially anything named 'Laser Tag Neon' or anything you added recently without thinking hard about it. Run a full antivirus scan on the machine you play on, and keep an eye out for unexpected PowerShell windows or unfamiliar files appearing in your download folders. Treat the official Discord and any recent dev posts as compromised until the team confirms otherwise, and stick to the community server the developers pointed to in the meantime. If you grabbed the game during its summer surge and never touched the Workshop, your risk is far lower, but a quick scan costs nothing and buys you peace of mind while the dust settles.
The CriticalPixel take
Valve owes players a real answer here, and the silence is the most disappointing part of the whole mess. A malware dropper made it onto the Workshop of one of the most-played party games on the platform, the developer's accounts got hijacked in the same wave, and the company that runs the storefront has not said a single word about it. Workshop moderation has been a known weak spot for years, and every incident like this proves that the 'subscribe and forget' model needs stronger vetting behind it before strangers can ship code to millions of trusting players. Credit to the security researcher who caught the dropper and to the community that spread the warning faster than any official channel managed to. For now, the burden falls on players to clean up their subscriptions and scan their own machines, which is a weak place to leave the people paying for the games and the developers getting their accounts stolen out from under them.
MECCHA CHAMELEON is a charming, silly hide-and-seek game that deserved a summer defined by streamer chaos and clip-worthy fails, not a malware headline. The fix in update 3.1.0 and the community's quick warnings appear to have contained the worst of it, but the underlying Workshop trust problem is not going away with one patch. Subscribe carefully, scan often, and watch for an actual statement from Valve about how a dropper like this slipped through in the first place. We will update this story if the developer or Valve confirms the second-stage payload or the full scope of the hijacked accounts.