Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » NPM malware packages target Roblox users with data-stealing malware
Global Security

NPM malware packages target Roblox users with data-stealing malware

AdminBy AdminNovember 8, 2024No Comments3 Mins Read
Malicious NPM Packages
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 8, 2024Ravi LakshmananOpen source / malware

Malicious NPM packages

The new campaign targeted an npm package repository with malicious JavaScript libraries designed to infect Roblox users with open source malware such as Indebtedness and Blank-grabber.

“This incident highlights the alarming ease with which threat actors can attack supply chains by exploiting trust and human error in the open source ecosystem and using readily available malware, public platforms such as GitHub to host malicious executables, and communication channels such as Discord and Telegram for C2 operations to bypass traditional security measures.” — Socket security researcher Kirill Boichenko said in a report shared with The Hacker News.

Cyber ​​security

The list of malicious packages is as follows –

It should be noted that “node-dlls” is an attempt on the part of the threat actor to impersonate a legitimate node-dll package that offers doubly linked list implementation for JavaScript. Likewise, rolimons-api is a cheat option Rolimon API.

Malicious NPM packages

“While there are unofficial wrappers and modules — such as rolimones The Python package (downloaded more than 17,000 times) and Rolimons The Lua module on GitHub — the rolimons-api malicious packages sought to exploit developers’ trust in familiar names,” Boychanka noted.

The fake packages include obfuscated code that downloads and executes Skuld and Blank Grabber, families of stealing malware written in Golang and Python, respectively, that are capable of collecting a wide range of information from infected systems. The resulting data is then transmitted to the attacker via a Discord or Telegram webhook.

Cyber ​​security

In a further attempt to bypass security measures, the malware binaries are extracted from a GitHub repository (“github(.)com/zvydev/code/”) controlled by the threat actor.

The popularity of Roblox in recent years has led to threat actors actively promoting fake packages to both developers and users. Several earlier this year harmful packages like noblox.js-proxy-server, noblox-ts and noblox.js-async were found to mimic the popular noblox.js library.

Because bad actors use widespread package trust to push packages that were printed, developers are encouraged to check package names and carefully study the source code before downloading them.

“As open source ecosystems grow and more developers rely on shared code, the attack surface expands and threat actors look for more opportunities to inject malicious code,” said Boychanka. “This incident highlights the need for increased awareness and robust security practices among developers.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.