The campaign, which began at the start of August 2023, revolves around malicious packages impersonating the legitimate noblox.js, a popular Node.js Roblox API wrapper. Roblox developers are being targeted by a new malware called Luna Grabber. The malware is being distributed through malicious npm packages that impersonate legitimate software. Luna Grabber can steal sensitive data from victims’ web browsers, Discord applications, and local system configurations.
The malware was downloaded appr