Overview
- Last weekend independent researcher Feint found a Steam Workshop map called Laser Tag Neon that briefly opened a command prompt, wrote a .bat file to a player’s Documents folder, and used PowerShell to fetch a second-stage payload.
- The developers released update 3.1.0 to patch the custom-map execution flaw, removed the identified maps including Chroma Grid Arena, and say the official Meccha Chameleon build is safe after applying the update.
- While investigating the maps a developer’s backup PC became infected, attackers used that access to bypass Discord two-factor authentication, change server permissions, and ban staff, taking control of the nearly 100,000-member official server.
- Feint’s analysis showed infection required launching a malicious map rather than merely subscribing to it and that the second-stage payload behaved like a Remote Access Trojan, so players who ran suspect maps are advised to run full malware scans and check Documents, temp folders, startup entries and Task Scheduler.
- The incident highlights gaps in user-generated content review and the risk to investigators and communities, and the developers have wiped the infected backup, contacted Discord Support, warned users not to trust messages in the hijacked server, and stand ready to set up a replacement server if recovery fails.