EGW-NewsMeccha Chameleon Workshop-kart sprer skadelig programvare: Hva du bør vite
Meccha Chameleon Workshop-kart sprer skadelig programvare: Hva du bør vite
277
Add as a Preferred Source
0
0

Meccha Chameleon Workshop-kart sprer skadelig programvare: Hva du bør vite

Denne artikkelen er tilgjengelig på følgende språk

Meccha Chameleon has been the year's strangest success story, and this week it added the year's strangest security scare. The $6 hide-and-seek game from Japanese developers lemorion1224 and haganeiro_fn sold 15 million copies in under a month, enough to make it the best-selling title of 2026 so far, past EA Sports FC, Resident Evil Requiem, Forza Horizon 6, ARC Raiders, and Slay the Spire II. For June, it ranked second only to Fortnite in PC revenue across a set of western markets, ahead of Counter-Strike 2, Valorant, and League of Legends, according to Newzoo figures shared by GamesIndustry.biz. Then some of its Workshop maps started quietly dropping malware.

The problem surfaced in a post on Medium by a user named Feint, picked up by Kotaku and then PC Gamer. Feint started digging after friends flagged something odd during a match: a black console window that popped up for about a second while a Workshop map was downloading. What he found was a map that looked completely normal but hid a dropper.

"...a seemingly ordinary workshop map that contained what appears to be a malware dropper, despite having passed workshop review."

— Feint

The folder held only standard Unreal Engine 5 asset files, no executables and no scripts, which is exactly why it cleared review. The payload sat inside a Blueprint dressed up as an ambient or lighting controller. On the affected maps it ran on its own as the level loaded, wrote a batch file into the player's Documents folder, then launched a hidden PowerShell process to fetch a second script from an outside server and run it. Feint's verdict was blunt: the item is "very likely malicious," even if he couldn't watch every link in the chain execute. He couldn't think of a legitimate reason for a map to write a batch file into your Documents folder and then pull down and run another one from the internet.

For a while, the second stage was a black box, because the server was offline when the first analysis ran. A later update to the write-up closed that gap, and it's the worst part: the recovered script installed a Remote Access Trojan, handing an attacker remote control of infected PCs. That turns this from an oddity into a real compromise for anyone who launched an affected map before patching.

The first flagged map was Laser Tag Neon. After it came down, another called Chroma Grid Arena went up in its place, which is the pattern to expect, one listing pulled and a fresh one seeded behind it. Both leaned on brand-new uploader accounts with comments and ratings switched off, the kind of listing worth skipping on sight.

Developer Haganeiro confirmed the fix in a post from the devs on X. Update 3.1.0 closes the vulnerability that let Workshop maps execute code, and the studio said the malware is disabled on the affected maps both before and after the patch. All currently identified malicious maps have been removed, though nothing stops new ones from appearing later.

The trouble didn't stop at maps. The game's official Discord, with close to 100,000 members, was hacked in the same stretch. In a Steam blog post, the studio said it had contacted Discord support and might stand up a new server if the old one couldn't be recovered. Developer lemorion1224 laid out the chain: a system engineer's PC was infected while fixing the map vulnerability, and the attacker used that foothold to bypass the engineer's two-factor authentication, rewrite server permissions, and ban the staff. One reply from Jeff on X, "Your discord is fucked man," caught the mood. Players were warned off clicking any suspicious links posted on the compromised server.

If you played custom Meccha Chameleon maps recently, the cleanup is simple. Update to 3.1.0. Run a scan with something like Malwarebytes. Check your Documents and Temp folders for unfamiliar, recently created.bat files, and look through your startup entries and Task Scheduler for anything you don't recognize. Subscribing to a map on its own doesn't trigger anything; the code fires when the match starts, so if you only subscribed and never launched it, unsubscribing is enough.

I don't reach for competitive hide-and-seek myself, since my gaming hours go to slower, story-driven worlds, so this was never going to be my main game. What keeps me reading is the story around it: a $6 debut that outsold nearly everything, climbing from 5 million sales in just 10 days to a genre nobody saw coming, then a Workshop pipeline turned against its own players. I'd still play a few rounds with friends, but I'd patch to 3.1.0 first and stick to popular maps with real comment histories.

Ikke gå glipp av nyheter og oppdateringer om esport! Registrer deg og motta ukentlig artikkeloversikt!
Registrer deg

There's a larger point under the specifics. Meccha Chameleon climbed on user content and social virality, and that same open, user-driven surface is what got exploited. Its low price and low spec needs, the traits Newzoo's analyst credited for the commercial run, also mean a huge, casual audience that mostly won't think twice about a flashy community map. Scale, open modding, and a crowd that isn't security-minded make a tempting target, and this won't be the last attempt. PC Gamer's review still calls the base game "a delightfully elevated take on hide-and-seek," and the malware doesn't change that. It raises the cost of ignoring where your Workshop downloads come from.

Legge igjen en kommentar
Likte du artikkelen?
0
0

Kommentarer

FREE SUBSCRIPTION ON EXCLUSIVE CONTENT
Receive a selection of the most important and up-to-date news in the industry.
*
*Only important news, no spam.
SUBSCRIBE
LATER