Node.js LTX Stealer Emerges as New Threat to Login Credentials
ID: c0611add-6886-538a-aa52-b1e277e54c45
STIX ID: report--c0611add-6886-538a-aa52-b1e277e54c45
Feed Name: GBHackers
LTX Stealer is a Node.js–based infostealer distributed inside deceptive Inno Setup installers (e.g., Negro.exe) that drops a bundled Node.js payload (updater.exe) to a hidden update-like folder, escalates privileges via LSASS token impersonation to run as SYSTEM, and uses Bytenode bytecode plus large encrypted archives to evade detection; it harvests Chromium browser credentials, cookies, session tokens, and cryptocurrency wallet data, and leverages Supabase and Cloudflare-backed infrastructure with observable domains, IPs, and file hashes while being marketed as low-cost Stealer-as-a-Service.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
