logo

Evolving npm Package Campaign Targets Roblox Devs, for Years

ID: be197646-4a7c-5110-bba6-37ef007af728

STIX ID: report--be197646-4a7c-5110-bba6-37ef007af728

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-09-03

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers report an ongoing supply-chain campaign (active since at least August 2023) in which attackers publish malicious npm packages that mimic the popular noblox.js library to target Roblox game developers. The packages deliver Luna Grabber and other payloads (including QuasarRAT), steal Discord tokens and system data, use obfuscated postinstall code and typosquatting/starjacking to appear legitimate, add registry-based persistence tied to the Windows Settings app, and attempt to disable third-party and built-in antivirus protections; despite takedowns, malicious packages continue to appear on the npm registry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.