Roblox devs under attack by new malicious npm campaign

Roblox homepage
(Image credit: Roblox)

Cybercriminals were, once again, spotted impersonating legitimate businesses, as they try to steal valuables from software developers. This time around, researchers from Checkmarx saw fake Roblox npm packages, whose true purpose is to deploy a remote access trojan (RAT) called Quasar.

Roblox is an online platform where users can create and play games made by other users, using a game creation system called Roblox Studio. It features a virtual currency called Robux for in-game purchases and has over 214 million monthly active users.

In this campaign, crooks were using typosquatting (giving malware a name similar to a legitimate file that developers could download and run by mistake), and deployed multiple packages to the npm repository, in hopes that someone will pick it up.

Quasar Remote Access Trojan

It’s an old strategy that worked well in the past, and seems to have worked well in this instance, too. According to the researchers, the four malicious packages that were identified, have had almost 200 downloads, combined, before being spotted and removed.

The noblox.js-async package had 74 downloads, noblox.js-thread 117 downloads, noblox.js-threads 64 downloads, and noblox.js-api 64 downloads.

“By mimicking the popular 'noblox.js' library, attackers have published dozens of packages designed to steal sensitive data and compromise systems," Checkmarx researchers said in a report.

"The attackers of this campaign have employed techniques including brandjacking, combosquatting, and starjacking to create a convincing illusion of legitimacy for their malicious packages."

To further improve the perceived legitimacy of these packages, the crooks also listed the source repository as noblox.js.

Developers that don’t spot the ruse and download these packs will receive the Quasar Remote Access Trojan, which is hosted on a GitHub repository. At the same time, they will lose their Discord tokens, and have their Microsoft Defender Antivirus updated to not spot the malware.

"Central to the malware's effectiveness is its approach to persistence, leveraging the Windows Settings app to ensure sustained access," the researchers added. "As a result, whenever a user attempts to open the Windows Settings app, the system inadvertently executes the malware instead."

Via The Hacker News

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A white padlock on a dark digital background.
GitHub is hiding malware disguised as games, legitimate software
Image depicting a hand on a scanner
New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
North Korean Lazarus hackers launch large-scale cyberattack by cloning open source software
North Korean flag with a hooded hacker
North Korean hackers are posing as software development recruiters to target freelancers
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
Latest in Security
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Latest in News
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently revealing the full cast for Avengers: Doomsday, and I think it's going to be a long-winded announcement
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news