Those Roblox npm downloads could be infected with malware

An abstract image of padlocks overlaying a digital background.
(Image credit: Shutterstock)

Cybersecurity researchers have once again found (and eradicated) malicious npm packages, this time delivering ransomware and password-stealing trojans on unsuspecting users.

Pretending to be Roblox JavaScript libraries, the two malicious npm packages were named noblox.js-proxy and noblox.js-proxies, and use typo-squatting to present themselves to anyone looking for the legitimate Roblox API wrapper called noblox.js-proxied, by altering a single letter in the library's name.

“These typosquatting packages mimic noblox.js, a popular Roblox game API wrapper that exists on npm as both a standalone package, along with legitimate variants such as noblox.js-proxied (ending in ‘d’ not ‘s’),” shares Sonatype’s security researcher, Juan Aguirre.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Noblox.js is an open source JavaScript API for the popular game Roblox. According to Aguirre, the library, which has clocked over 700,000 downloads, is commonly used to create in-game scripts that interact with the Roblox website.

A sinister prank?

Analysis of the malicious libraries has revealed that their authors had stuffed them with malware, the MBRLocker ransomware that impersonates the notorious GoldenEye ransomware, a password stealing trojan, as well as a spooky video.

Aguirre points out that the two typosquatting libraries couldn’t do any real damage since they were caught not long after they were uploaded, though they still managed to clock 281 and 106 downloads respectively. 

“...but it’s clear what type of scale the threat actors were hoping for going after such a popular component,” notes Aguirre.  

Interestingly, this attempt to deliver ransomware comes just a few days after Sonatype researchers had uncovered an audacious attempt by threat actors to hijack the account of the developer of the widely used UAParser.js library to replace the legitimate code with malicious one infused with malware and trojans.

While Sonatype believes the fake roblox libraries were probably planted as a prank, the incident is a further indication that adversaries aren’t going to stop abusing popular open source repositories anytime soon.  

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
A white padlock on a dark digital background.
GitHub is hiding malware disguised as games, legitimate software
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
The Python banner logo on a computer screen running a code editor.
More malicious Python packages are on the loose, experts warn
Image depicting a hand on a scanner
New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages
GitHub Webpage
A cracked malicious version of a Go package lay undetected online for years
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras