A Node.js API wrapper for Roblox.
Installing the package invokes an obfuscated postinstall script. It fingerprints the Windows environment, downloads a remote executable, writes it to the temporary directory, and starts it detached.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
examples/cleanPlayers.jsView on unpkg · L34Package source references weak cryptographic algorithms.
lib/datastores/setDatastoreEntry.jsView on unpkg · L32Source contains an obfuscated payload loader that reconstructs and executes hidden code.
postinstall.mjsView on unpkg · L1Install-named source file stages remote content through filesystem writes and execution.
postinstall.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/util/relog.jsView on unpkgThis report applies to noblox-asset.js@7.4.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
examples/cleanPlayers.jsView on unpkg · L34Package source references weak cryptographic algorithms.
lib/datastores/setDatastoreEntry.jsView on unpkg · L32Source contains an obfuscated payload loader that reconstructs and executes hidden code.
postinstall.mjsView on unpkg · L1Install-named source file stages remote content through filesystem writes and execution.
postinstall.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/util/relog.jsView on unpkg