The biggest indie “friendslop” game of 2026 appears to be delivering malware via Steam Workshop — How to protect your PC (and what to do next)

In the ever-evolving landscape of gaming, the indie sensation Meccha Chameleon has captured the attention of players across the globe, including my circle of friends. If you find yourself among the ranks of its enthusiastic players, it may be prudent to revisit the custom maps you’ve downloaded from the Steam Workshop. Recent findings suggest a potential security concern that warrants your attention.

Feint, a contributor on Medium.com, has conducted an in-depth analysis revealing that certain workshop maps linked to Meccha Chameleon may harbor malicious scripts, commonly referred to as malware, which could infiltrate players’ PCs. This investigation was sparked by observations from friends who noticed an unusual command prompt window flickering during the automatic download of a custom map while entering specific game lobbies.

At first glance, the files associated with these custom maps appeared to conform to standard practices, featuring typical Unreal Engine 5 asset containers devoid of any obvious executables or scripts. However, Feint’s diligent examination unearthed a more insidious issue: a Blueprint actor with a naming inconsistency hidden within the map’s metadata. Designed to mimic an ambient controller, this Blueprint bore an outdated internal name that raised suspicions.

According to Feint’s findings, this Blueprint is programmed to execute automatically upon the map’s loading. Once activated, it stealthily injects a batch file into the user’s Documents folder on their Windows PC—a troubling development. When triggered, this batch file initiates a concealed PowerShell process, circumventing execution policies, and attempts to connect to an external server to download a secondary script. The outcome of Feint’s tests indicated that this download failed, leaving the precise intentions behind the script shrouded in mystery.

No name for the malware, but a map shouldn’t act like this

While the ultimate purpose of this peculiar script remains uncertain, one fundamental principle stands clear: a game’s map should never engage in writing or executing scripts outside its designated folder. This behavior is a definitive indicator of malware. A similar situation arose with Wallpaper Engine, which was found to be infecting users with malicious software. In response, Valve, the parent company of Steam, took decisive action to eliminate the infected files, although they cautioned that such incidents could inadvertently recur.

A look at Meccha Chameleon’s Steam Workshop page.
(Image credit: Valve)

Join us on Reddit at r/WindowsCentral to share your insights and discuss our latest news, reviews, and more.

AppWizard
The biggest indie "friendslop" game of 2026 appears to be delivering malware via Steam Workshop — How to protect your PC (and what to do next)