AUTO-UPDATED

The biggest indie "friendslop" game of 2026 appears to be delivering malware via Steam Workshop — How to protect your PC (and what to do next)

Security researcher Feint has discovered malicious scripts hidden within custom Steam Workshop maps for the popular indie game Meccha Chameleon, which can execute unauthorized batch files on Windows PCs.

Key Points

  • Malicious maps use a disguised Blueprint actor to inject batch files into the user's Documents folder upon loading.
  • The script attempts to launch a hidden PowerShell process to download secondary payloads from an external server.
  • Suspicious map listings are characterized by recently created Steam accounts with disabled comments and ratings.
  • Users are advised to avoid downloading new custom maps and to run antivirus scans if they have recently installed community content.
  • Valve has been notified of the security vulnerability, though the company has not yet confirmed the removal of the specific files.

Why it Matters

This incident highlights ongoing security risks within the Steam Workshop, where malicious actors can exploit game engines to bypass standard user protections. It serves as a reminder for PC gamers to exercise caution when downloading community-created content, as even popular platforms remain vulnerable to sophisticated malware distribution.
Windows Central Published by c.cale.hunt@gmail.com (Cale Hunt) , Cale Hunt
Read original