LWA-2026-11910 MAL-2026-16059 ↗ confirmed malware

rojo-rbx@1.4.3

Malicious code in rojo-rbx (npm)

T1105 · Ingress Tool TransferT1547.001 · Registry Run Keys / Startup FolderT1059.007 · JavaScriptT1059.003 · Windows Command Shell

Analysis

The install hook (scripts/install.js) is a Windows-only downloader and persistence implant. On install it fetches a remote VBS payload from hxxps://l81[.]me/updater[.]vbs (a URL shortener), writes it to %APPDATA%\Rojo\rojo-sync.vbs, registers a Run-key entry (HKCU\Software\Microsoft\Windows\CurrentVersion\Run, value name RojoClientSync) that executes the dropped script via wscript.exe, and launches it hidden and detached. The payload is fetched and executed at install time with no user interaction.

analyzed by
Leitwacht
first seen
Sep 6, 2026, 03:50 AM
analyzed
Sep 6, 2026, 03:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.