logo

Node.js LTX Stealer Emerges as New Threat to Login Credentials

ID: c0611add-6886-538a-aa52-b1e277e54c45

STIX ID: report--c0611add-6886-538a-aa52-b1e277e54c45

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

LTX Stealer is a Node.js–based infostealer distributed inside deceptive Inno Setup installers (e.g., Negro.exe) that drops a bundled Node.js payload (updater.exe) to a hidden update-like folder, escalates privileges via LSASS token impersonation to run as SYSTEM, and uses Bytenode bytecode plus large encrypted archives to evade detection; it harvests Chromium browser credentials, cookies, session tokens, and cryptocurrency wallet data, and leverages Supabase and Cloudflare-backed infrastructure with observable domains, IPs, and file hashes while being marketed as low-cost Stealer-as-a-Service.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.