Security researcher Feint has discovered malicious scripts hidden within custom Steam Workshop maps for the popular indie game Meccha Chameleon, which can execute unauthorized batch files on Windows PCs.
Key Points
- Malicious maps use a disguised Blueprint actor to inject batch files into the user's Documents folder upon loading.
- The script attempts to launch a hidden PowerShell process to download secondary payloads from an external server.
- Suspicious map listings are characterized by recently created Steam accounts with disabled comments and ratings.
- Users are advised to avoid downloading new custom maps and to run antivirus scans if they have recently installed community content.
- Valve has been notified of the security vulnerability, though the company has not yet confirmed the removal of the specific files.