Anime, manga, and games, with a take · A Yukimedia publication

← all stories games 4 sources · Jul 26 · · Updated

Meccha Cameleon Discord Server Hijacked After Mod Map Malware Incident

The incident shows how a security response itself can create a new attack vector when a developer's verification machine becomes the entry point for a Discord takeover.

Key Facts

  • The official Discord server for Meccha Cameleon was hijacked on July 26 after the server creator's account was taken over and all administrators were banned.
  • Malware was found in user-created mod maps on Steam Workshop, prompting a security patch in version 3.1.0 on July 25 that disabled malware execution.
  • Developer Haganeiro's backup PC became infected during malware verification, leading to the Discord account compromise; the PC was not a development machine.
  • The developers denied claims that the game itself contained malware, stating the game is 100% virus-free and logs showed no tampering.
  • The Discord server was restored by July 27, with a new invite link issued and all attacker accounts banned.

Reporting from 4 sources: ASCII.jp, Denfaminicogamer, GameBusiness.jp, Game Spark.

Meccha Cameleon Discord Server Hijacked After Mod Map Malware Incident

The official Discord server for the indie game Meccha Cameleon was hijacked on July 26, just hours after developers released a security patch for malware found in user-created mod maps on Steam Workshop. Developer Lemorion reported that the server creator's account was taken over and all administrators were banned, leaving the team unable to manage the server. The incident began on July 25 when reports surfaced that some custom maps distributed via Steam Workshop contained malware capable of arbitrary code execution. The developers released version 3.1.0 that same day, which included a security patch that disabled malware execution in mod maps. However, during the verification process, one developer's backup PC became infected, leading to the Discord account compromise. The hackers then posted false claims that the game itself contained a Remote Access Tool, which Lemorion denied, stating the game is 100% virus-free. The infected PC was not a development machine, and no evidence of game file tampering was found. The server was restored by July 27, with all attacker accounts banned and a new invite link issued. Meccha Cameleon, a multiplayer hide-and-seek game where players camouflage into scenery, has sold over 15 million copies since its June 10 release.

Co-creator HAGANEIRO said the vulnerability in mod maps allowed unrestricted URL execution and unauthorized file generation. The security patch in version 3.1.0, released at 21:00 on July 25, blocked those capabilities. The same update added a collaboration map with Garten of Banban.

The infected backup PC was not a development machine, and logs showed no remote access or file changes to the game itself. HAGANEIRO stated that the PC has been completely reset. The hackers posted messages mimicking the fictional hacker group DedSec from Ubisoft's Watch Dogs series. They also claimed the game contained a Remote Access Tool, which Lemorion called "disinformation to cause confusion and misdirection."

Discord's official X account responded to the developers' support request. By July 27 at approximately 7:30, the server was restored. Lemorion transferred the server's highest authority to a secure account separate from the compromised one. All attacker accounts were banned, and a new invite link was issued. On X, many users praised the development team's crisis management.

Version 3.2.0, released on July 26, added 12 new emotes including "orz" and a handstand pose. The patch notes state that mod maps are now safe to use and that Steam support has confirmed the fix. Meccha Cameleon is available on Steam for 790 yen, with a 15% discount to 671 yen until August 3.

Synthesized by Yomimono from the 4 cited sources below, including Japanese-language reporting where cited, then editorially reviewed before publishing.

Sources