Package Managers Ruin Everything
283 segments
Now, this channel doesn't often get into
gaming because the last time I did
gaming, well, it did not end too well.
But, it turns out that there is a game
out right now that had a massive hack to
it. And the funny part about the this
hack is that it actually reminds me of a
different hack that has just recently
happened to Notepad. For those that are
not familiar, the game we are talking
about is Mecha Chameleon. And of course,
Mecha Chameleon is a game in which you
attempt to hide in plain sight by
coloring your body and all that to look
like the surroundings and see who can
really actually hide the longest. And of
course, this game just blew up in
popularity. Everybody wanted to play. It
seems like a very fun streaming game.
It's kind of like Among Us style in
which people can get together and laugh
and all that and have fun and
friendship. I don't know anything about
that.
Anyways, the game continued to have such
popularity because one of the aspects of
the game is that user-generated content
was allowed. Users could make their own
levels and of course, people could play
those levels. Now, this is how the hack
happened. Can you believe it?
Effectively, a package manager for game
hacked everybody. They're bad in
TypeScript, they're bad in Rust, and
they're bad in Mecha Chameleon. So,
we're going to go over this most
excellent blog by Kale Kugler. It's a
two-click remote execution for this
game. This is our future, by the way.
Noth- nothing's safe, okay? You just You
just You can't go on the internet
anymore, okay? It's disallowed. It's not
We're
I In fact, I'm calling it today. We're
canceling the internet. Before we cancel
the internet, quick thank you from the
sponsor.
>> Hey, Brian.
Don't forget, scrum planning's later.
>> [sighs]
>> No.
No.
Can't do this.
>> Product manager here. We've decided to
put YOU ON CALL.
>> [laughter]
>> I CAN'T DO I CAN'T DO on call.
>> You're on call?
>> Lucky.
>> What are you saying?
>> With Sentry, on call is so [music] much
fun. It has all of our errors, logs,
spans, metrics, replays, [music] and
even releases in one spot. It has all
the context we need to solve any bug,
even if half the time Sentry beats me
[music] to the fix anyway.
Just cuz software development's torture
doesn't mean on call has to be.
>> Wow, that's amazing. Does Sentry also
attend my meetings?
>> Well, that's the best [music] part.
>> No.
>> Sentry can't actually make on call fun,
but it can make it less scary.
Everything you need to [music] fix real
issues in one place.
>> Buckaroo, got that 6:00 p.m. postmortem
planning. Don't forget.
>> All right, welcome back. Now, to
understand how this hack works, you
first have to understand a little bit
about how you can generate custom maps.
Now, the thing about Mecca Chameleon is
that you don't have to mod the game to
add new maps. Instead, you can just
create a new Unreal Engine 5 map, and
you can put it in you can package it all
together in a dot pack file. Now, I
don't know what exactly a dot pack file
is, but it's an Unreal Engine specific
item, and then you can upload it to the
Steam's official workshop for others to
play. Now,
what's a workshop? It turns out a
workshop is really just arbitrary file
delivery because Steam workshop items
such as maps are essentially just
folders. That means you can upload or
put in whatever you want into a workshop
item. Now, if you check out Steam's
official documentation and you're
looking at uploaded entries from item
authors, these workshop items, it does
warn you that your submission tool
should accept just the file formats that
your game client expects to load. Now,
in the case of Mecca Chameleon, it turns
out they just well, they just accepted
everything. But, accepting everything
itself doesn't actually pose any sort of
immediate risk. That means your workshop
item can have a beautiful map, it can
have textures and audios, it can have
preview images, and it could have very
destructive or credential stealing bat
files. All a part of the workshop item.
And this just will go on to anybody's
computer that downloads it. Now, none of
this explains exactly how the hack
works. So, let's actually go through the
real part. So, now when a lobby starts
and the a custom map is selected, those
that don't have the map are prompted
with the window that says, "Hey,
you got to download this custom map."
So, of course, you go to the custom map,
you you press the subscribe button, bam!
And just like that, you get yourself
hacked. Yes, actually that is the
moment. Right then and there, that is
actually how you get hacked. Now, when
it comes to Unreal Engine, which by the
way, I don't have any experience in
this, so I'm not deeply familiar, but it
turns out there's all these different
events that you can actually hook into.
And one of those events is begin play.
Now, something that begin play can do is
launch a URL. And now you're probably
immediately thinking, "Wait a second,
launch a URL? This kind of sounds like
that one hack." Yes, it actually sounds
exactly like that one hack. That one
hack, of course, is when Windows Notepad
had a markdown RCE. Yes, Notepad, if you
did not know, actually ended up changing
for like the first time in 20 years, and
they immediately made it exploitable.
Now, if you do not know the exploit for
Windows Notepad, it was actually pretty
simple. You would go to a Notepad, you
would open it up, it happened to be a
markdown, and look at that. Look at that
beautiful little link right there. Well,
you're going to go and you're going to
want to go click that link, right? Well,
it turns out the link doesn't contain an
HTTP address, instead it contains a
file, a URI file. Beautiful, right?
Well, it turns out that if you clicked
on a link, it would just open anything.
Now, naturally, this was actually rather
difficult to exploit because you had to
get some sort of malicious program onto
the computer first. And then, by
clicking the link, so it's kind of like
this two-step process, get malicious
package, and then get somebody to link,
you could take advantage of the Windows
system. Now, of course, the Mecca
Chameleon one uses this exact same
vulnerability, but it was a bit more
sinister. So, now, when you see this,
this open URL, you can immediately
understand where this is going. Yes, in
fact, the underlying method is almost
identical. It turns out it ends up
opening shell execute W. So, whatever
you hand it, if you hand it a file URI,
it will just open that up. Now, remember
just a little bit ago when I told you
about how these Steam Workshop items,
they're just folders and you can put
whatever you want inside of that.
Remember that? It It was just a moment
ago. How did you forget? By the way, for
those that use real operating systems,
we call these directories, but on
Windows, Windows, am I right, boys? They
call them They call them folders, you
know, because you put files
in folders, Manila folders actually
specifically, and then you put those in
a box that's a hard drive, and then you
put them
on the top shelf of your garage never to
look at them again. So, by using a
folder, you can upload bat files or EXE
files to do whatever you want to do, and
then with the begin a play event that
gets executed the moment your map gets
loaded into Mecca Chameleon, hey, no
restart needed, just go and download it
there, bucko. The moment that executes,
botta bing, botta boom, it can open any
arbitrary file on your system, which
happens to be a file that it just got
done downloading, and bam, you're taking
advantage of, okay, son? You just got
wrecked. And if you go through Kael's
blog, that's exactly what you see. He
ends up just simply doing a a nice
little who am I. You know, honestly,
like who
who who who am I?
The name?
What? Now, I think something that is
actually a lot more dangerous and people
just need to know about. And the reason
really why I wanted to do this video is
that there's a lot of indie games out
there that allow custom user content.
And just like Mecha Chameleon, that was
a mega popular game, but there's a lot
of these games that probably contain
identical exploits. Which means you
should be a little bit more careful.
Now, you wouldn't install an NPM
package, would you? That's because
you're a developer. You're very very
very very smart. But what you don't
realize is that installing an NPM
package could potentially execute a post
script if you don't have a post install
script if you don't have all the
security and things set up for that not
to happen. And that is how a lot of
these worms, these Shahhaled worms, have
been going about. Now, it turns out that
exact same style of exploit is happening
with games. So, really the PSA is that
you're going to get hacked. You're going
to just stop down- Again, the internet,
I'm calling it. We're turning it off.
We're done. We're returning to monkey,
okay? No more of this crap. But the real
the actually the real takeaway is that
agents kind of are scary, right? You're
downloading and putting things on your
machine at a rate in which you've never
been able to put on before, okay? You
think installing NPM modules was like
bad. Now, you got agents putting who
knows what. We have skills in which have
hidden HTML which can take advantage of
your system. You have all sorts of ways
to get prompt injected. You know, so
just hey, be careful out there.
Understand what's happening. Understand
what's being downloaded. And just
remember, just because a bunch of people
use something does not mean it's safe.
Just like Mecha Chameleon, one of the
hottest games out there. Turns out just
had a massive vulnerability in which to
who knows what information was taken.
Also, I'd like to do a special shout out
at the end of this blog, which by the
way, you should go read. It's a very
excellent blog. He says doing security
research like this is often a thankless
job. So, this goes out to you, Kale.
Really appreciated the blog. Awesome
write-up. The name
is the Prime Agent. Okay, that's not
what it looks like. Okay, that's not
what it looks like. What I was going to
show you, okay, I didn't mean for this
to happen, but what I was going to show
you is that I can draw really straight
lines. I bet I'd be pretty good at Mecha
Chameleon, okay? Agent.
Ask follow-up questions or revisit key timestamps.
This video examines a critical security vulnerability found in the popular game 'Mecha Chameleon,' which allows for remote code execution. By leveraging the game's Steam Workshop support for custom maps, attackers can deliver malicious files that are automatically executed via Unreal Engine's 'begin play' event. This exploit functions similarly to a past vulnerability in Windows Notepad, highlighting the risks inherent in games that allow unchecked user-generated content and the broader danger of blindly downloading packages or assets.
Videos recently processed by our community