rojo-rbx@1.4.3
Malicious code in rojo-rbx (npm)
T1105 · Ingress Tool TransferT1547.001 · Registry Run Keys / Startup FolderT1059.007 · JavaScriptT1059.003 · Windows Command Shell
Analysis
The install hook (scripts/install.js) is a Windows-only downloader and persistence implant. On install it fetches a remote VBS payload from hxxps://l81[.]me/updater[.]vbs (a URL shortener), writes it to %APPDATA%\Rojo\rojo-sync.vbs, registers a Run-key entry (HKCU\Software\Microsoft\Windows\CurrentVersion\Run, value name RojoClientSync) that executes the dropped script via wscript.exe, and launches it hidden and detached. The payload is fetched and executed at install time with no user interaction.
- analyzed by
- Leitwacht
- first seen
- Sep 6, 2026, 03:50 AM
- analyzed
- Sep 6, 2026, 03:51 AM
Related advisories
- ulid-intel@2.12.3
- node-request-utils@1.0.0
- mfa-js@1.0.4
- discord-mfa@3.0.0
- hydration-dim-ui@1.0.0
- space-items@1.0.0
- runtime-health@1.0.1
- @evial/init-helper-djkwt@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.