
Meccha Chameleon players have been warned to update the game and avoid its original Discord server after malicious Steam Workshop maps infected PCs and helped attackers compromise a developer account.
The security issue was first detailed by independent researcher Feint, who investigated reports of command prompt windows appearing as players loaded custom Meccha Chameleon maps.
Feint discovered that a Workshop map named Laser Tag Neon contained code capable of writing a batch file to a player’s Documents folder. That file then attempted to use PowerShell to download and execute a second malicious payload from an external server.
The map was removed, although Feint later reported that another malicious upload named Chroma Grid Arena had appeared in its place.
めっちゃカメレオンサーバーのセキュリティを突破され、サーバー製作者のアカウントが乗っ取られ、管理者が全員BANされたためこちらから手を出せません。
現在discordに問い合わせ中ですが、通報のご協力をお願いします。 https://t.co/PmT7O7c7Jz— LEMORION🌌レモリオン (@lemorion1224) July 25, 2026
Meccha Chameleon update patches Workshop exploit
Developer Haganeiro confirmed that the vulnerability was fixed with Meccha Chameleon update 3.1.0.
“The vulnerability in the custom maps described in today’s update 3.1.0 has been fixed, so there are no issues after applying it,” the developer said.
The team also said the malware had been disabled on the identified maps, including for players who had not yet installed the update.
Feint later recovered and analyzed the second-stage payload, reporting that it installed a Remote Access Trojan capable of giving an attacker persistent remote control over an infected computer.
Players who launched suspicious Workshop maps before updating have been advised to run a full malware scan. Feint also recommended checking the Documents and temporary folders for recently created .bat files.
According to the researcher, subscribing to a malicious map alone was not enough to trigger the malware. The infected content had to be launched in a match.

Old School RuneScape comes to indie mega-hit Meccha Chameleon with Lumbridge map

Meccha Chameleon fans are now playing it in real life by hiding figures in public
《めっちゃカメレオン》
公式discordサーバーの件とMODマップのマルウェアの件がごっちゃになっていますが、
MODマップの件については引用の通りで解決済みであり、Steamサポートにも安全を確認済みです。
discord乗っ取りの件はほぼ解決済みで、48時間以内にサーバーは復旧する見込みです。… https://t.co/s4j4iQMqJO— LEMORION🌌レモリオン (@lemorion1224) July 26, 2026
Official Discord taken over after engineer PC infected
The incident then spread to the game’s official Discord server, which had nearly 100,000 members.
Developer LEMORION said a system engineer used a backup computer while investigating the malicious maps and infected the device with malware.
The attacker allegedly used the compromised computer to access the engineer’s Discord account, bypass two-factor authentication, change server permissions, and ban the game’s staff members.
“The hacker bypassed the engineer’s two-factor authentication on Discord, altered the server permissions, and banned all the staff members,” LEMORION explained.
‼️ Hang in there, it gets worse: MECCHA CHAMELEON's Discord server was taken over after malware infected a system engineer’s PC and compromised an administrator account, allowing the attacker to bypass two-factor authentication and remove staff members from the server.
Community… https://t.co/QnMu6nMODE pic.twitter.com/3lsXSxbnIe
— International Cyber Digest (@IntCyberDigest) July 25, 2026
The developer stressed that the affected device had no access to Meccha Chameleon’s source code, game files, or Steam developer accounts. It also denied messages posted through the hijacked server claiming that the official game build contained malware.
Players have been warned not to trust announcements or follow links posted in the original Discord while the developer waits for Discord Support to respond. A replacement community server has been created in the meantime.
The official Steam version of Meccha Chameleon is considered safe after updating to version 3.1.0, but anyone who launched custom maps before the patch may still want to scan their PC.