Cyware Feed
new-luna-grabber-poses-as-roblox-packages,-strikes-npm

New Luna Grabber Poses as Roblox Packages, Strikes NPM

Malicious actors are targeting Roblox developers with a new malware called Luna Grabber, distributed through npm packages that impersonate legitimate software. These fake packages, including noblox.js-vps, noblox.js-ssh, and noblox.js-secure, house malicious multi-stage payloads. This campaign underscores the recurring strategy of threat actors employing typosquatting as a tactic to deceive developers.