Meccha Chameleon malware: what to do if you launched a Workshop map
July 28, 2026Meccha Chameleon’s developers say the custom-map vulnerability has been fixed. Here is how to assess a Workshop subscription or pre-patch map launch and what Windows security steps to take.
Meccha Chameleon’s developers say the custom-map vulnerability behind recent malware reports has been fixed. In a July 25, 2026 Steam Community update, the team said the preceding version had resolved the issue and made it impossible to execute unrelated files such as malware. The post also said Steam Support had confirmed the fix.
That is the developers’ current-status statement, not a separate public security audit from Valve. It also does not answer what may have happened on a Windows PC that loaded a suspicious custom map before the patch.
For players assessing possible exposure, the key distinction is whether they merely subscribed to a Workshop item or actually started a match on a suspicious map. That distinction comes from independent researcher Feint’s technical analysis, not from Valve or the game’s developers.
Is Meccha Chameleon safe now?
The developers’ position is that the vulnerability is fixed. In its official update, the team wrote: “This issue was resolved in the previous version, making it impossible to execute unrelated files such as malware.” The same post said Steam Support had confirmed this.
In a separate July 25 developer statement, co-developer HAGANEIRO said update 3.1.0 fixed the custom-map vulnerability and that malware had been disabled for the affected maps before and after the update.
These statements address the game’s current status. They do not establish whether code may already have run during an earlier pre-patch session, so players should choose the response below that matches what they did.
Check which exposure scenario applies to you

You subscribed to a Workshop item but did not start a match
Feint reported: “The malware is executed when you start the match, not when you subscribe to the map.” On that researcher’s account, subscribing by itself was not the reported execution event.
This finding has not been presented as a Valve confirmation, but it means a subscription alone should not be treated as equivalent to launching the reported malware. Confirm that the game has updated before opening custom content, and avoid launching unfamiliar Workshop maps while details about the incident remain incomplete.
The available evidence does not show that the base game, every Workshop download or every subscriber was infected. No verified number of affected players has been supplied.
You launched a suspicious custom map before the July 25 patch
This is the scenario that warrants security checks. Feint identified Laser Tag Neon in the initial investigation and later reported that the map had been removed. The researcher subsequently named Chroma Grid Arena as another active malicious map.
Those names come from Feint’s independent investigation. They are not a complete Valve-confirmed list, and the available evidence does not establish that every other map discussed in community posts was malicious.
If you started a match on either named map, or on another map you have a specific reason to suspect, before installing update 3.1.0, run the Windows security checks below. Patching the game may prevent the reported route from being used again, but the patch alone cannot determine what happened during an earlier session.
You played only after installing update 3.1.0 or later
The developers say update 3.1.0 fixed the custom-map vulnerability. If you did not launch a suspicious map before that update, the supplied evidence does not place you in the same pre-patch exposure scenario. That conclusion is based on the developers’ current statement and should not be interpreted as an independent audit of every Workshop item. Keep the game updated and continue to assess unfamiliar community content cautiously.
What to do after a possible pre-patch map launch
- Stop launching custom maps until the game is updated. Confirm through Steam that Meccha Chameleon has installed the latest available update.
- Run a malware scan through Windows Security. Follow Microsoft’s official Defender scanning instructions rather than commands copied from community posts.
- Run Microsoft Defender Offline. Microsoft describes Defender Offline as its most complete scan option and says it can help identify threats that hide while Windows is running.
- Take account precautions from a separate, known-clean device if you have a credible exposure concern. Feint reported that an analysed second-stage payload installed a remote-access trojan. Valve and the developers have not independently confirmed that finding, and it does not prove that any particular player’s passwords, files or accounts were accessed.
- Protect important accounts. As a precaution, change the passwords for your primary email and Steam accounts from the known-clean device, enable two-factor authentication where available, and review active sign-in sessions. Apply the same precaution to other sensitive accounts if you used them on the potentially affected PC.
- Escalate if malware returns or the PC continues to behave unusually. Microsoft’s malware-removal troubleshooting guidance recommends Defender Offline for malware that keeps returning. Microsoft also says a reset, restore or reinstall may be required if malware has caused irreversible changes.
If you have a concrete reason to believe someone still has remote access to the PC, disconnect it from the internet and seek qualified technical support. Do not attempt to remove suspected malware by deleting unfamiliar files, changing the Registry or running unverified commands from community posts.
What is confirmed and what remains unverified
The official Steam Community feed says the vulnerability was fixed and that Steam Support confirmed the fix. A July 26 official post also said the game’s Discord server had been restored and that “all the hackers” had been banned. That Discord update does not independently validate every technical claim made about the Workshop incident.
Feint’s investigation supplies the documented map names, the reported start-a-match execution point and the later RAT classification. Those findings should remain attributed to the researcher because no supplied Valve statement confirms the complete technical chain.
The available sources do not establish how many people launched the maps, how many computers were infected, whether any particular player’s data was accessed, or a complete list of malicious Workshop items. Claims that every subscriber, every Workshop user or the base game was infected are not supported.
For most players, the practical question is therefore narrow: did you start a suspicious custom-map match before update 3.1.0, or did you only subscribe or play after updating? If you launched a potentially involved map before the fix, use Microsoft’s official scanning tools and take proportionate account precautions. If detections return or there are signs of continued access, seek qualified help.


