Meccha Chameleon Vulnerability Allowed Malware to Spread Through Steam Workshop Maps

 

A security vulnerability in the game Meccha Chameleon enabled malicious custom maps stored on Steam Workshop to infect users with malware. The vulnerability was patched by the game’s developers, who noted that the issue was related to the custom content feature.

The issue was initially uncovered when some players reported that a command prompt window was flashing as Steam was downloading a custom workshop map. 
Security researcher Feint investigated the matter and found that one of the maps entitled Laser Tag Neon had the ability to deploy malware dropper despite having passed the Steam Workshop review process.

Feint shared his findings on social media, noting that another map entitled Chroma Grid Arena had replaced the malicious content, which indicated that the threat was still present.
It appears that the vulnerability could enable threat actors to utilize the game’s custom workshop feature to deploy malware onto users’ computers disguised as legitimate content.

Meccha Chameleon developer Haganeiro confirmed that the issue had been resolved in version 3.1.0. He noted that the malware had been disabled both prior to the update and following its deployment, thus limiting the potential impact of the vulnerability. 
The vulnerability was part of a larger security incident that involved the game’s Discord server, which housed 90 thousand members. The server was hacked, with the attacker rewriting its permissions and removing the developer team from the server. According to lemorion_1224, the Discord compromise occurred when the system administrator’s computer was infected with malware during the mitigation efforts of the vulnerability.

The attacker was able to bypass the two-factor authentication of the server and modify its settings, banning several members of the development team. 
It was revealed that the compromised machine belonged to the backup server, and it was later wiped clean.

The developer warned the community against clicking the suspicious links that were distributed via the hacked discord server while mitigation measures were being implemented. It appears that a wide range of potential attack surfaces could be utilized to threaten the community.

Gaming platforms have a diverse range of threat surfaces that can be utilized by attackers to compromise users’ computers. 
In addition to the game binaries themselves, the custom content and third-party tools such as Discord can be threatened. Players should ensure they have the latest versions of the software and avoid interacting with suspicious links or content.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: