logo

Weaponized Code: LTX Stealer Abuses Node.js to Bypass Antivirus

ID: 8f678d9a-8549-5db1-b9a3-0ff0a7c2e330

STIX ID: report--8f678d9a-8549-5db1-b9a3-0ff0a7c2e330

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-02-12

Date Updated: 2026-04-23

Author: Ddos

...
...

LTX Stealer is a sophisticated Windows credential stealer distributed via a heavily obfuscated Inno Setup installer (e.g., Negro.exe) that embeds a full Node.js runtime and compiles JavaScript into bytecode to evade analysis; it drops an updater.exe payload, uses decrypt.py to extract Chromium browser credentials, cookies and session tokens, hunts for cryptocurrency wallets, and is offered as a low-cost Stealer-as-a-Service using Supabase/Cloudflare infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.