A malicious Steam Workshop mod for the game Meccha Chameleon was found to contain a hidden remote code execution payload embedded in Unreal Engine asset registry metadata. The mod dropped a batch file that used PowerShell to fetch a second-stage RAT payload. The developer patched the vulnerability the same day it was reported. Separately, a Discord server associated with the game was compromised and used to spread false claims that the game's official update was malicious — an analysis of the patched game binary found no evidence of tampering, concluding the Discord incident was a hoax designed to harm the game's reputation.
•21m watch time
374 Impressions