Security Vulnerability in Custom Maps

A recent security incident involving the game Meccha Chameleon has left players wary after a vulnerability was discovered in the game's Steam Workshop support. According to reports, malicious actors were able to distribute malware through custom maps, bypassing standard review processes. Users noted unusual behavior, such as command prompt windows appearing during map downloads.

The issue was initially brought to light by a community member who identified a suspicious file hidden within a map titled Laser Tag Neon. The developer, Haganeiro, acknowledged the problem and released update 3.1.0 to close the exploit. In a public statement on X, the developer confirmed: «The vulnerability in the custom maps described in today's update 3.1.0 has been fixed, so there are no issues after applying it. We have also confirmed that the malware is disabled for the affected maps both before and after the update.»


Discord Server Compromise

The situation for the development team worsened when their official Discord server, which boasts a community of nearly 100,000 members, fell victim to a hack. The breach led to unauthorized changes in server permissions and the mass banning of staff members.

Developer lemorion_1224 explained that the breach was a direct result of the ongoing security efforts. A system engineer’s secondary PC was infected with malware while they were working to resolve the Steam Workshop vulnerabilities. The attacker utilized this access to bypass two-factor authentication.


Current Status and Warnings

The developers are actively working to resolve the Discord situation. Key updates regarding the incident include:

  • The affected engineer's backup computer has been wiped and removed from the development workflow.
  • The team is in contact with Discord Support to regain control of the server.
  • If the current server cannot be reclaimed, a new official hub will be launched.

Players are strongly advised to remain cautious. The development team has urged the community to avoid clicking any suspicious links posted on the compromised Discord server while investigations continue.