Recommended Free Tools
Yes, this was a real npm supply-chain campaign. Attackers published packages impersonating the legitimate noblox.js Roblox API wrapper, then used npm installation hooks to deploy information stealers, Discord-token theft tools, QuasarRAT, and Windows persistence. The documented activity ran in repeated waves from at least August 2023 through late August 2024; the available evidence does not establish that it remains active in 2026.
If you installed a suspicious package, treat the machine and its credentials as potentially compromised—not just the project dependency.
As an Amazon Associate I earn from qualifying purchases.
What the campaign targeted
The campaign targeted Roblox developers using JavaScript or Node.js for administration tools, Discord bots, automation scripts, moderation systems, and other community tooling. It did not amount to a confirmed breach of Roblox’s platform. The primary target was the developer’s Windows workstation and the credentials accessible from it.
The legitimate noblox.js project is a Node.js library for interacting with Roblox-related web functionality. That made its name, package structure, and developer audience attractive to impersonators. Roblox Studio plugins and assets are a separate software category; this campaign concerned npm dependencies installed in Node.js projects.
#1 Best Overall
A campaign that changed over time
- Early August 2023: ReversingLabs identified a malicious package wave.
- August 22, 2023: ReversingLabs published its analysis of packages delivering Luna Grabber.
- August 25, 2023: Roblox warned developers that more than a dozen malicious packages had been identified.
- August 2023–August 2024: Checkmarx described repeated publication, takedowns, and replacement packages.
- August 29, 2024: Checkmarx reported newer package families, QuasarRAT deployment, credential theft, and Windows persistence.
These were successive waves, not necessarily one unchanged package or binary available continuously for the entire period. The reported evidence supports describing the campaign as active from at least August 2023 through late August 2024—not as a campaign confirmed to be active today.
The 2023 reporting attributed 963 downloads before takedown to that reported wave. That figure is not a confirmed total for the broader campaign or a count of infected developers.
How the fake packages looked legitimate
The attackers used several forms of package deception:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Brandjacking: using the established
noblox.jsidentity. - Combosquatting: adding plausible suffixes such as
-async,-api, or-threads, making the name look like an official extension. - Starjacking: linking package metadata to the genuine GitHub repository, potentially making the fake package appear more popular or affiliated than it was.
- Structure mimicry: copying the legitimate library’s layout so a quick visual inspection would be less revealing.
- Obfuscation: hiding malicious logic in an install script, including confusing characters and difficult-to-read code.
Repository links, download counts, stars, and a familiar package name are useful signals, but none proves authenticity. Verify the exact package name and follow the installation link from the project’s official documentation or repository.
Reported package names
These are historical indicators from the cited reports, not a complete list and not proof that every version had identical behavior.
| Reported wave | Package names | Additional detail |
|---|---|---|
| 2023 | noblox.js-vps, noblox.js-ssh, noblox.js-secure |
Reported versions included noblox.js-vps 4.14.0–4.23.0, noblox.js-ssh 4.2.3–4.2.5, and noblox.js-secure 4.1.0 and 4.2.0–4.2.3. |
| 2024 | noblox.js-async, noblox.js-threads, noblox.js-thread, noblox.js-api |
Checkmarx described dozens of packages and multiple takedowns; this is not an exhaustive list. |
The legitimate package is noblox.js, but the package name alone is not enough: inspect the maintainer, official project links, release history, scripts, dependencies, and lockfile entry.
Why postinstall.js mattered
npm supports lifecycle scripts such as preinstall, install, and postinstall. npm runs these at defined points in the installation process, and a malicious package can abuse that behavior to execute code before the developer has reviewed the package’s application logic.
A postinstall script is not automatically malicious. Legitimate packages may use lifecycle scripts to compile native components, generate files, or complete setup. An unexpected, obfuscated, or unrelated install script should nevertheless receive heightened scrutiny.
npm install --ignore-scripts
npm ci --ignore-scripts
--ignore-scripts prevents npm lifecycle scripts from running for that installation. It is a risk-reduction control, not a malware guarantee: application code can still be malicious, and legitimate packages may fail until required setup is performed manually. Use it especially for initial inspection or controlled CI builds, then evaluate any package that genuinely requires scripts.
What the malware reportedly did
Capabilities varied between samples and waves.
Earlier wave: Luna Grabber
ReversingLabs reported that the 2023 packages delivered Luna Grabber, an information stealer capable of harvesting data from browsers, Discord, and the local system.
Rank #3
Later wave: theft and QuasarRAT
Checkmarx reported that later samples searched for Discord authentication tokens and system information, sending stolen material to attacker-controlled infrastructure. Some samples added QuasarRAT as a secondary payload. QuasarRAT can provide broad remote access to a compromised Windows host, but it should not be presented as a payload installed by every package in the campaign.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteCheckmarx also reported attempts to stop Malwarebytes and add detected disk drives to Windows Defender’s exclusion list. Other samples downloaded executables identified in the analysis as cmd.exe and Client-built.exe, storing them under C:WindowsApi. These are sample-specific indicators; their presence alone does not prove infection.
Reported Windows persistence
Checkmarx identified a modification at:
HKCUSoftwareClassesms-settingsShellOpencommand
This is a current-user Registry location associated with the Windows ms-settings protocol handler. The reported malware abused that handler so opening Windows Settings could trigger a downloaded executable. It does not mean Windows Settings itself was vulnerable.
To perform a read-only check in PowerShell:
Get-ItemProperty `
-Path 'HKCU:SoftwareClassesms-settingsShellOpencommand' `
-ErrorAction SilentlyContinue
A suspicious value deserves investigation, but do not automatically delete the key. Preserve evidence and confirm what created it first.
How to audit a project safely
1. Search manifests and lockfiles
Check every dependency record, not just the current package.json. Review:
Rank #4
package.jsonpackage-lock.jsonnpm-shrinkwrap.jsonyarn.lockpnpm-lock.yaml
On macOS, Linux, or a compatible shell:
grep -RInE 'noblox.js-(vps|ssh|secure|async|threads?|api)'
package.json package-lock.json npm-shrinkwrap.json yarn.lock pnpm-lock.yaml 2>/dev/null
On Windows PowerShell:
Select-String -Path package.json,package-lock.json,npm-shrinkwrap.json,yarn.lock,pnpm-lock.yaml `
-Pattern 'noblox.js-(vps|ssh|secure|async|threads?|api)'
These are investigative examples, not official vendor detections. A clean search does not prove that a workstation is clean: names can change, and the package may have been removed from the current project.
2. Inspect the dependency tree
npm ls --all
npm ls noblox.js
npm audit
npm audit is useful for known vulnerabilities, but it is not a malware scanner and does not prove that a maintainer or package is authentic. Also investigate transitive dependencies, global packages, npm caches, CI environments, and recently changed lockfiles.
3. Review lifecycle scripts without executing the package
For a package being considered, inspect its metadata and source in an isolated environment. Look for:
"scripts": {
"preinstall": "...",
"install": "...",
"postinstall": "..."
}
Do not run suspicious package code merely to inspect it. If deeper analysis is required, use a disposable, isolated environment without production credentials.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match4. Review installation and security history
Check npm commands, PowerShell or Command Prompt history, endpoint alerts, project timestamps, and account activity around the first suspicious installation. A package takedown does not uninstall copies already present or undo stolen credentials.
Best Value
How to check the Windows workstation
If the package’s install script ran, inspect for:
- Unexpected executables in user-writable locations.
- The reported
C:WindowsApidirectory or similarly named recent directories. - Unexpected Windows Defender exclusion paths.
- The reported
ms-settingsRegistry handler. - New scheduled tasks, startup entries, or security-tool alerts.
To view Defender exclusion paths:
Get-MpPreference | Select-Object -ExpandProperty ExclusionPath
Output varies by Windows version, permissions, and Defender configuration. Run a trusted, up-to-date endpoint scan and consider an offline scan if compromise is suspected. The campaign reportedly attempted to weaken security controls, so a clean routine scan should not be treated as conclusive by itself.
What to do if a suspicious package ran
- Isolate the machine. Disconnect it from the network if active compromise is suspected.
- Stop using it for sensitive work. Do not continue signing in to Roblox, Discord, GitHub, npm, cloud consoles, or production systems from that device.
- Use a known-clean device. Revoke Discord sessions and tokens, change passwords, rotate Roblox, GitHub, npm, cloud, webhook, and API credentials, replace exposed SSH keys and personal access tokens, and enable multifactor authentication.
- Preserve evidence. Save relevant project files, lockfiles, timestamps, endpoint alerts, and Registry information before destructive cleanup if the project has business or community value.
- Scan and recover. Use current endpoint protection, including an offline scan where appropriate. If downloaded malware or persistence executed, a clean rebuild or known-good restore is safer than relying only on deleting the package folder.
- Audit connected systems. Look for unauthorized commits, new secrets, altered CI workflows, added dependencies, suspicious npm publishing activity, or unusual Discord and cloud sessions.
- Warn collaborators. Tell teammates and community members who may have installed the same historical package.
Changing only a Roblox password is insufficient if browser credentials, Discord tokens, GitHub tokens, SSH keys, or cloud credentials were available to the compromised Windows account.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Controls that help prevent a repeat
- Install the exact package linked by the official project documentation; do not assume a suffix is an official extension.
- Review maintainer identity, publication history, repository ownership, dependencies, and lifecycle scripts.
- Commit and review lockfiles. They improve reproducibility, but they can reproduce a malicious version too.
- Use
npm ci --ignore-scriptsin controlled builds where project requirements allow it. - Run development tools under a non-administrator Windows account.
- Keep production credentials out of developer workstations and local configuration files.
- Use MFA and rotate tokens after suspected exposure.
- Monitor CI dependency changes and require review for new packages or install scripts.
- Keep Windows security features and tamper protection enabled.
For an individual hobby project, these controls are usually more valuable than buying an enterprise platform. Teams with many repositories, CI/CD pipelines, production secrets, or compliance obligations may additionally consider GitHub Dependabot, Socket, Snyk Open Source, Sonatype Nexus Lifecycle, Checkmarx One, or managed endpoint protection. Those tools improve visibility and policy enforcement; none guarantees that every malicious package will be identified.
What remains uncertain
The cited reporting does not establish the exact number of victims, whether every package came from one operator, whether the infrastructure remained active after the 2024 reporting, or whether a newer wave occurred after August 2024. It also does not show that noblox.js itself was malicious. The documented issue was malicious dependency impersonation aimed at Roblox-related Node.js developers and their workstations.
For the original reporting, see Checkmarx, ReversingLabs, the Roblox developer warning, and the official noblox.js repository.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




