The biggest indie "friendslop" game of 2026 appears to be delivering malware via Steam Workshop — How to protect your PC (and what to do next)

The biggest indie "friendslop" game of 2026 appears to be delivering malware via Steam Workshop — How to protect your PC (and what to do next) 图片 1
The biggest indie "friendslop" game of 2026 appears to be delivering malware via Steam Workshop — How to protect your PC (and what to do next) 图片 2
The biggest indie "friendslop" game of 2026 appears to be delivering malware via Steam Workshop — How to protect your PC (and what to do next) 图片 3
The biggest indie "friendslop" game of 2026 appears to be delivering malware via Steam Workshop — How to protect your PC (and what to do next) 图片 4

It seems like everyone these days is playing the insanely popular indie game Meccha Chameleon on PC, my friends included. If you've also played, you're going to want to double-check what custom, user-created maps you've downloaded from the Steam Workshop.

Worse, if you've already downloaded some custom maps for the game, I strongly suggest you A) finish reading about the issue, and B) check your Steam library.

A security researcher who goes by Feint on Medium.com recently posted a lengthy analysis breaking down their findings. They posit that some workshop maps associated with Meccha Chameleon are quietly being rigged to drop malicious scripts (aka malware) onto players' PCs.

Feint began the investigation after friends noticed a command prompt window flashing briefly as Steam downloaded a custom workshop map for the game. These downloads are handled automatically as you load into certain game lobbies.

On the surface, the custom map's files looked totally normal, with standard Unreal Engine 5 asset containers and a lack of evident executables or scripts.

Digging deeper, however, Feint discovered the real problem: a Blueprint actor with a naming mismatch buried inside the map's metadata. It was built to look like an ambient controller, but an outdated internal name tipped off the researcher.

According to Feint, the Blueprint is built to run automatically the moment the map loads. When it does, it injects a batch file into the gamer's Documents folder on their Windows PC. Not good.

Once triggered, the batch file sneakily launches a hidden PowerShell process with bypassed execution policy before calling out to an outside server to download a second script.

Feint's testing resulted in that download failing, so it remains unclear what exactly was intended to be sent to infected PCs.

No name for the malware, but a map shouldn't act like this

A look at Meccha Chameleon's Steam Workshop page. (Image credit: Valve)

Although the final goal of the odd script is deba…

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论