Malware found in popular indie game Meccha

Meccha indie game infected with malware through custom Steam Workshop maps, posing a security risk to players with malicious code downloading files.

Malware found in popular indie game Meccha - meccha malware
Malware found in popular indie game Meccha

A malware exploit was found in custom maps for the indie game Meccha Chameleon, which were distributed through the Steam Workshop. The security breach was discovered after an independent investigation identified suspicious command-line instructions hidden inside community-created scenarios.

The investigation revealed that the malicious code was embedded in Unreal Engine Blueprints and generated an s.bat file within the Documents folder, spawning a hidden PowerShell process to download secondary scripts from a remote server.

Cybersecurity researcher Feint discovered the suspicious behavior within a workshop map titled Laser Tag Neon. Loading the custom scenario under Windows triggered a brief Command Prompt window, revealing the malicious logic.

Related: PS2 Emulator Gets Multiplayer on Android

The developers of Meccha Chameleon confirmed the vulnerability and released patch 3.1.0 to block further exploitation. They did not find the core security flaw in official game files but rather in the system responsible for loading modified maps downloaded via Valve’s platform.

Although the attacker’s server returned a 404 error during the investigation, preventing analysts from identifying the final payload, the code served no legitimate function within game maps. Laser Tag Neon was subsequently removed.

The exploit activated upon executing the map or joining a lobby running the infected scenario. Users who accessed Laser Tag Neon are advised to unsubscribe, run a full system scan, and check for s.bat files without opening them manually.

Related: Weekly roundup New infosec products debut July 17

During the investigation, a developer executed the infected map on a secondary computer, leading to compromised credentials and an unauthorized takeover of the official Discord server. The attacker banned team members and posted false claims alleging that update 3.1.0 contained a trojan, which the developers firmly denied.

The affected machine was formatted, and the developers confirmed it held no access to official build distribution files. They addressed the exploit in version 3.1.0, neutralizing malicious content across older versions as well.

Launched in June, Meccha Chameleon has emerged as one of 2026’s largest indie successes, surpassing 15 million copies sold in under a month.

Leave a Reply