Multiplayer prop‑hunt game Meccha Chameleon faces a serious security issue after user‑made maps were found to contain trojan‑style malware, leading to a hacked Discord server and fake VR product listing. Developers have issued a patch and advise players to stick to official maps.

Key Takeaways

  • Malicious user‑made maps were discovered
  • Official Discord server was hacked and admins banned
  • Developers released a patch that restores safe play

Meccha Chameleon, a prop‑hunt multiplayer title that surged in popularity on Steam after its early‑June launch, has hit a serious security snag. A community member known as “Feint” reported that several community‑uploaded maps functioned as Trojan horses, delivering hidden malware to players’ PCs.

The map titled “Lazer Tag Zero” triggered a command‑prompt window during download, prompting Feint to inspect the package. The investigation revealed a “malware dropper” embedded in the map files, leading to its rapid removal from the Steam Workshop after a Medium exposé.

Within days, additional malicious maps surfaced, and the game’s official Discord server fell victim to a coordinated hack. Creator Lemorion_1224 confirmed that the server’s creator account was hijacked, all admins were banned, and the team could not intervene from their side.

Steam’s game page was updated to reassure players that the core game remains safe, provided they avoid third‑party maps. Hackers even fabricated a non‑existent “Meccha Chameleon VR” listing on the Meta Quest store, prompting a public removal request.

Historical Background

Since its debut in June 2024, Meccha Chameleon has attracted thousands of players for its fast‑paced hide‑and‑seek mechanics. Community‑generated content has been a cornerstone of its replayability, but this incident underscores the risks of unsupervised user uploads.

Why This Matters

BozokMedia analysis shows that a single compromised map can expose thousands of gamers to ransomware or credential theft, eroding trust in indie platforms that rely on community mods.

“In the era of user‑generated content, continuous security scanning is non‑negotiable for any live service.”
Did You Know?: The first known game‑mod malware incident dates back to 2012’s “Counter‑Strike: Source” cheat packs.

Frequently Asked Questions

Q1: Are official game files infected?
A: No. The malware is confined to specific community maps.

Q2: How can I protect myself?
A: Stick to maps hosted on the official Steam Workshop and keep your antivirus active.