October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
VGSources
Blog

Fake npm Packages Targeted Roblox Developers From 2023 Through 2024—How to Check for Infection

Attackers impersonated noblox.js with malicious npm packages from 2023 through 2024. Here’s what they did, who was at risk, and how developers can check projects and Windows systems.
Length7 min Posted Quest giverVGSources Team
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes, this was a real npm supply-chain campaign. Attackers published packages impersonating the legitimate noblox.js Roblox API wrapper, then used npm installation hooks to deploy information stealers, Discord-token theft tools, QuasarRAT, and Windows persistence. The documented activity ran in repeated waves from at least August 2023 through late August 2024; the available evidence does not establish that it remains active in 2026.

If you installed a suspicious package, treat the machine and its credentials as potentially compromised—not just the project dependency.

As an Amazon Associate I earn from qualifying purchases.

What the campaign targeted

The campaign targeted Roblox developers using JavaScript or Node.js for administration tools, Discord bots, automation scripts, moderation systems, and other community tooling. It did not amount to a confirmed breach of Roblox’s platform. The primary target was the developer’s Windows workstation and the credentials accessible from it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The legitimate noblox.js project is a Node.js library for interacting with Roblox-related web functionality. That made its name, package structure, and developer audience attractive to impersonators. Roblox Studio plugins and assets are a separate software category; this campaign concerned npm dependencies installed in Node.js projects.

A campaign that changed over time

  • Early August 2023: ReversingLabs identified a malicious package wave.
  • August 22, 2023: ReversingLabs published its analysis of packages delivering Luna Grabber.
  • August 25, 2023: Roblox warned developers that more than a dozen malicious packages had been identified.
  • August 2023–August 2024: Checkmarx described repeated publication, takedowns, and replacement packages.
  • August 29, 2024: Checkmarx reported newer package families, QuasarRAT deployment, credential theft, and Windows persistence.

These were successive waves, not necessarily one unchanged package or binary available continuously for the entire period. The reported evidence supports describing the campaign as active from at least August 2023 through late August 2024—not as a campaign confirmed to be active today.

The 2023 reporting attributed 963 downloads before takedown to that reported wave. That figure is not a confirmed total for the broader campaign or a count of infected developers.

How the fake packages looked legitimate

The attackers used several forms of package deception:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Brandjacking: using the established noblox.js identity.
  • Combosquatting: adding plausible suffixes such as -async, -api, or -threads, making the name look like an official extension.
  • Starjacking: linking package metadata to the genuine GitHub repository, potentially making the fake package appear more popular or affiliated than it was.
  • Structure mimicry: copying the legitimate library’s layout so a quick visual inspection would be less revealing.
  • Obfuscation: hiding malicious logic in an install script, including confusing characters and difficult-to-read code.

Repository links, download counts, stars, and a familiar package name are useful signals, but none proves authenticity. Verify the exact package name and follow the installation link from the project’s official documentation or repository.

Reported package names

These are historical indicators from the cited reports, not a complete list and not proof that every version had identical behavior.

Reported wave Package names Additional detail
2023 noblox.js-vps, noblox.js-ssh, noblox.js-secure Reported versions included noblox.js-vps 4.14.0–4.23.0, noblox.js-ssh 4.2.3–4.2.5, and noblox.js-secure 4.1.0 and 4.2.0–4.2.3.
2024 noblox.js-async, noblox.js-threads, noblox.js-thread, noblox.js-api Checkmarx described dozens of packages and multiple takedowns; this is not an exhaustive list.

The legitimate package is noblox.js, but the package name alone is not enough: inspect the maintainer, official project links, release history, scripts, dependencies, and lockfile entry.

Why postinstall.js mattered

npm supports lifecycle scripts such as preinstall, install, and postinstall. npm runs these at defined points in the installation process, and a malicious package can abuse that behavior to execute code before the developer has reviewed the package’s application logic.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A postinstall script is not automatically malicious. Legitimate packages may use lifecycle scripts to compile native components, generate files, or complete setup. An unexpected, obfuscated, or unrelated install script should nevertheless receive heightened scrutiny.

npm install --ignore-scripts
npm ci --ignore-scripts

--ignore-scripts prevents npm lifecycle scripts from running for that installation. It is a risk-reduction control, not a malware guarantee: application code can still be malicious, and legitimate packages may fail until required setup is performed manually. Use it especially for initial inspection or controlled CI builds, then evaluate any package that genuinely requires scripts.

What the malware reportedly did

Capabilities varied between samples and waves.

Earlier wave: Luna Grabber

ReversingLabs reported that the 2023 packages delivered Luna Grabber, an information stealer capable of harvesting data from browsers, Discord, and the local system.

Later wave: theft and QuasarRAT

Checkmarx reported that later samples searched for Discord authentication tokens and system information, sending stolen material to attacker-controlled infrastructure. Some samples added QuasarRAT as a secondary payload. QuasarRAT can provide broad remote access to a compromised Windows host, but it should not be presented as a payload installed by every package in the campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Checkmarx also reported attempts to stop Malwarebytes and add detected disk drives to Windows Defender’s exclusion list. Other samples downloaded executables identified in the analysis as cmd.exe and Client-built.exe, storing them under C:WindowsApi. These are sample-specific indicators; their presence alone does not prove infection.

Reported Windows persistence

Checkmarx identified a modification at:

HKCUSoftwareClassesms-settingsShellOpencommand

This is a current-user Registry location associated with the Windows ms-settings protocol handler. The reported malware abused that handler so opening Windows Settings could trigger a downloaded executable. It does not mean Windows Settings itself was vulnerable.

To perform a read-only check in PowerShell:

Get-ItemProperty `
  -Path 'HKCU:SoftwareClassesms-settingsShellOpencommand' `
  -ErrorAction SilentlyContinue

A suspicious value deserves investigation, but do not automatically delete the key. Preserve evidence and confirm what created it first.

How to audit a project safely

1. Search manifests and lockfiles

Check every dependency record, not just the current package.json. Review:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • package.json
  • package-lock.json
  • npm-shrinkwrap.json
  • yarn.lock
  • pnpm-lock.yaml

On macOS, Linux, or a compatible shell:

grep -RInE 'noblox.js-(vps|ssh|secure|async|threads?|api)' 
  package.json package-lock.json npm-shrinkwrap.json yarn.lock pnpm-lock.yaml 2>/dev/null

On Windows PowerShell:

Select-String -Path package.json,package-lock.json,npm-shrinkwrap.json,yarn.lock,pnpm-lock.yaml `
  -Pattern 'noblox.js-(vps|ssh|secure|async|threads?|api)'

These are investigative examples, not official vendor detections. A clean search does not prove that a workstation is clean: names can change, and the package may have been removed from the current project.

2. Inspect the dependency tree

npm ls --all
npm ls noblox.js
npm audit

npm audit is useful for known vulnerabilities, but it is not a malware scanner and does not prove that a maintainer or package is authentic. Also investigate transitive dependencies, global packages, npm caches, CI environments, and recently changed lockfiles.

3. Review lifecycle scripts without executing the package

For a package being considered, inspect its metadata and source in an isolated environment. Look for:

"scripts": {
  "preinstall": "...",
  "install": "...",
  "postinstall": "..."
}

Do not run suspicious package code merely to inspect it. If deeper analysis is required, use a disposable, isolated environment without production credentials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Review installation and security history

Check npm commands, PowerShell or Command Prompt history, endpoint alerts, project timestamps, and account activity around the first suspicious installation. A package takedown does not uninstall copies already present or undo stolen credentials.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to check the Windows workstation

If the package’s install script ran, inspect for:

  • Unexpected executables in user-writable locations.
  • The reported C:WindowsApi directory or similarly named recent directories.
  • Unexpected Windows Defender exclusion paths.
  • The reported ms-settings Registry handler.
  • New scheduled tasks, startup entries, or security-tool alerts.

To view Defender exclusion paths:

Get-MpPreference | Select-Object -ExpandProperty ExclusionPath

Output varies by Windows version, permissions, and Defender configuration. Run a trusted, up-to-date endpoint scan and consider an offline scan if compromise is suspected. The campaign reportedly attempted to weaken security controls, so a clean routine scan should not be treated as conclusive by itself.

What to do if a suspicious package ran

  1. Isolate the machine. Disconnect it from the network if active compromise is suspected.
  2. Stop using it for sensitive work. Do not continue signing in to Roblox, Discord, GitHub, npm, cloud consoles, or production systems from that device.
  3. Use a known-clean device. Revoke Discord sessions and tokens, change passwords, rotate Roblox, GitHub, npm, cloud, webhook, and API credentials, replace exposed SSH keys and personal access tokens, and enable multifactor authentication.
  4. Preserve evidence. Save relevant project files, lockfiles, timestamps, endpoint alerts, and Registry information before destructive cleanup if the project has business or community value.
  5. Scan and recover. Use current endpoint protection, including an offline scan where appropriate. If downloaded malware or persistence executed, a clean rebuild or known-good restore is safer than relying only on deleting the package folder.
  6. Audit connected systems. Look for unauthorized commits, new secrets, altered CI workflows, added dependencies, suspicious npm publishing activity, or unusual Discord and cloud sessions.
  7. Warn collaborators. Tell teammates and community members who may have installed the same historical package.

Changing only a Roblox password is insufficient if browser credentials, Discord tokens, GitHub tokens, SSH keys, or cloud credentials were available to the compromised Windows account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Controls that help prevent a repeat

  • Install the exact package linked by the official project documentation; do not assume a suffix is an official extension.
  • Review maintainer identity, publication history, repository ownership, dependencies, and lifecycle scripts.
  • Commit and review lockfiles. They improve reproducibility, but they can reproduce a malicious version too.
  • Use npm ci --ignore-scripts in controlled builds where project requirements allow it.
  • Run development tools under a non-administrator Windows account.
  • Keep production credentials out of developer workstations and local configuration files.
  • Use MFA and rotate tokens after suspected exposure.
  • Monitor CI dependency changes and require review for new packages or install scripts.
  • Keep Windows security features and tamper protection enabled.

For an individual hobby project, these controls are usually more valuable than buying an enterprise platform. Teams with many repositories, CI/CD pipelines, production secrets, or compliance obligations may additionally consider GitHub Dependabot, Socket, Snyk Open Source, Sonatype Nexus Lifecycle, Checkmarx One, or managed endpoint protection. Those tools improve visibility and policy enforcement; none guarantees that every malicious package will be identified.

What remains uncertain

The cited reporting does not establish the exact number of victims, whether every package came from one operator, whether the infrastructure remained active after the 2024 reporting, or whether a newer wave occurred after August 2024. It also does not show that noblox.js itself was malicious. The documented issue was malicious dependency impersonation aimed at Roblox-related Node.js developers and their workstations.

For the original reporting, see Checkmarx, ReversingLabs, the Roblox developer warning, and the official noblox.js repository.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More quests from Patch Notes

  1. How to Set Up a RedM (RDR2) Server in 2026: License Key, txAdmin and server.cfg, Step by StepBlog11min
  2. Best RedM (RDR2) Server Hosting in 2026: Comparing Four Hosts on Slots, Memory and PriceBlog10min
  3. How to Host a Mindustry Server in 2026: server-release.jar, Port 6567 and the Commands That MatterBlog7min
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.