A Node.js API wrapper for Roblox.
Importing the package executes an obfuscated downloader that launches an opaque executable. No install lifecycle trigger is declared.
Package source references dynamic require/import behavior.
examples/cleanPlayers.jsView on unpkg · L34Package source references weak cryptographic algorithms.
lib/datastores/setDatastoreEntry.jsView on unpkg · L32Source contains an obfuscated payload loader that reconstructs and executes hidden code.
lib/index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/util/relog.jsView on unpkgThis report applies to noblox-asset.js@7.6.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references dynamic require/import behavior.
examples/cleanPlayers.jsView on unpkg · L34Package source references weak cryptographic algorithms.
lib/datastores/setDatastoreEntry.jsView on unpkg · L32Source contains an obfuscated payload loader that reconstructs and executes hidden code.
lib/index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/util/relog.jsView on unpkg