Infostealer Campaign Targeting Roblox Developers via Malicious 'robase' Python Package and Fake Discord Job Offers

Infostealer Campaign Targeting Roblox Developers via (TL-2026-0845), also tracked as robase campaign, is a high-severity malware campaign, first published 2026-06-17. It has no confirmed attribution, affects Roblox Corporation Roblox (developer accounts, groups, games, Robux), maps to 17 MITRE ATT&CK techniques (T1005, T1036, T1059), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-0845

Threat ID
TL-2026-0845
Also known as
robase campaign, Roblox developer infostealer campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-06-17
Last reviewed
2026-06-17
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
gaming, game development, online entertainment, individual creators
Target regions
Global, North America, Europe
Detection rules
9
Indicators of compromise
22

Malware and tooling in Infostealer Campaign Targeting Roblox Developers via

Malware and tooling: BlankGrabber, Discord Injector, Skuld

An active social-engineering campaign targets Roblox game developers with infostealer malware delivered through fake Discord project-manager job offers and studio impersonation, distributing a malicious Python package named 'robase'. The malware steals authenticated browser sessions and the .ROBLOSECURITY token to bypass two-factor authentication, enabling theft of developer accounts, group ownership, entire published games, and Robux balances.

How Infostealer Campaign Targeting Roblox Developers via works

Since at least early 2026, threat actors have been running a persistent, financially and ownership-motivated social-engineering campaign against Roblox developers. The attack begins on Discord: operators pose as recruiters or legitimate game studios (e.g., impersonating 'Cheesy Studios') and dangle a paid project-manager role. After building rapport, they ask the target to 'install a Python package' or 'run a particular file' as part of supposed internal database or project tooling. The package named in confirmed victim accounts is 'robase', described to the victim as a 'database tool'. Shortly after installation, victims are forcibly logged out of Roblox on both PC and mobile, with attackers proceeding to seize the account, the developer group, the published game(s), and any Robux balance.

The core technique is session-token / cookie theft rather than password theft. Infostealers grab the authenticated browser session and the Roblox .ROBLOSECURITY cookie (and frequently Discord tokens), which are presented directly to the platform's servers — making two-factor authentication (2FA) irrelevant because the attacker is already authenticated as the victim. This same session-hijacking pattern lets the attacker pivot across Roblox, Discord and other accounts the stealer harvests.

The 'robase' lure sits within a broader, well-documented ecosystem of supply-chain attacks on the Roblox developer community across PyPI and npm. Related campaigns have published typosquatted/impersonating packages — including npm packages node-dlls, ro.dll, autoadv and two versions of rolimons-api — that deliver the Go-based Skuld infostealer and the Python-based Blank Grabber, and PyPI packages embedding a 'Discord Injector' that exfiltrates Discord tokens and skims payment-card data. These payloads commonly pull secondary executables and tooling from the Discord CDN and GitHub, and exfiltrate harvested data over Discord webhooks. Documented victims of the current Roblox-developer wave include 'The Shadow Network' (a game built by the Matziaris brothers), a 15-year-old developer (Jovan Rai) who was earning roughly 10,000 Robux/day and needed 30+ days to recover, and developer Mohamed Kaparoza, who documented the Discord-to-robase attack chain.

Mitigation centers on treating unsolicited Discord job offers that request software installation as hostile, testing unknown packages only in isolated virtual machines, reviewing and revoking active Roblox/Discord sessions, enabling Roblox 'Enhanced Protection' / account-security features, and deploying real-time endpoint malware detection. Because the attack defeats 2FA through stolen session material, response must include immediate session revocation and credential rotation, not just a password reset.

MITRE ATT&CK techniques used in TL-2026-0845

Collection

T1005 Data from Local System

Defense Evasion

T1036 Masquerading

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1102 Web Service; T1105 Ingress Tool Transfer

Initial Access

T1195 Supply Chain Compromise; T1566 Phishing

Discovery

T1217 Browser Information Discovery

Credential Access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

Impact

T1531 Account Access Removal

lateral-movement

T1550 Use Alternate Authentication Material

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1585 Establish Accounts; T1587 Develop Capabilities

Affected products and versions in Infostealer Campaign Targeting Roblox Developers via

  • Roblox Corporation — Roblox (developer accounts, groups, games, Robux)
    Vulnerable versions: accounts relying on session cookies / 2FA
  • Python Software Foundation — PyPI (Python Package Index)
    Vulnerable versions: malicious package 'robase'
  • OpenJS / npm — npm registry
    Vulnerable versions: node-dlls 1.0.0; ro.dll 1.0.0; autoadv 1.0.0; rolimons-api 1.1.0; rolimons-api 1.1.2
  • Discord Inc. — Discord (accounts, tokens, CDN abused for delivery/exfiltration)
    Vulnerable versions: session tokens
  • Microsoft — Windows
    Vulnerable versions: systems running the infostealer payloads

Remediation for Infostealer Campaign Targeting Roblox Developers via

Immediate actions

  • Treat any unsolicited Discord job/collaboration offer that asks you to install a package or run a file as malicious; do not install 'robase' or similar unverified packages
  • If compromise is suspected, immediately revoke all active Roblox sessions (Settings > Security > log out of all sessions) and all Discord sessions/authorized apps — a password reset alone does NOT invalidate stolen session tokens
  • Rotate the .ROBLOSECURITY token by logging out everywhere and re-authenticating, then re-enable 2FA
  • Contact Roblox support to recover hijacked groups/games and document all evidence (Discord messages, screenshots, timestamps) early

Workarounds

  • Disable or scope developer Discord DMs from non-contacts to reduce the social-engineering entry point
  • Use separate, hardened browser profiles or accounts for Roblox development so session cookies are not co-located with general browsing

Longer-term hardening

  • Only run unfamiliar packages or files inside an isolated virtual machine or sandbox, never on a machine with active Roblox/Discord sessions
  • Deploy real-time EDR/anti-malware with infostealer behavioral detection on developer endpoints
  • Enable Roblox Enhanced Protection / account-security features and hardware-backed or app-based 2FA
  • Pin and verify dependencies; vet PyPI/npm packages (publisher, age, download count, source repo) before install and avoid typosquats

Weaknesses (CWE) in Infostealer Campaign Targeting Roblox Developers via

CWE-506, CWE-829, CWE-522, CWE-1021

Timeline of Infostealer Campaign Targeting Roblox Developers via

  • Snyk and other researchers document waves of malicious PyPI packages targeting Discord and Roblox that steal credentials and payment information via an embedded 'Discord Injector', establishing the ecosystem this campaign builds on.
  • Socket.dev reports malicious npm packages (node-dlls, ro.dll, autoadv, rolimons-api 1.1.0/1.1.2) impersonating Roblox developer modules to deliver Skuld infostealer and Blank Grabber; packages saw 320+ downloads before removal.
  • A similar social-engineering campaign targets Roblox players with fake beta-test offers, foreshadowing the developer-focused recruitment lures.
  • ThreatLocker observes the 'Powercat' campaign delivering infostealers via fake game cheat/utility software to Roblox, Minecraft, GTA V, Discord and Telegram users.
  • 'The Shadow Network', a game by the Matziaris brothers, is compromised in the Roblox-developer infostealer wave.
  • 404 Media reports that attackers are hijacking entire Roblox games via these infostealer-driven account takeovers.
  • A 15-year-old developer (Jovan Rai) earning ~10,000 Robux/day reports 30+ days of recovery effort after account takeover; victims lose group ownership, games, and Robux balances.
  • Developer Mohamed Kaparoza documents being contacted on Discord, offered a project-manager role, asked to install 'robase' described as a database tool, then logged out of Roblox on PC and phone.
  • Malwarebytes publishes analysis describing the 'robase' Python-package lure delivered via fake Discord project-manager job offers and 'Cheesy Studios' impersonation, with session-token theft bypassing 2FA.

Sources cited for Infostealer Campaign Targeting Roblox Developers via

Threats related to Infostealer Campaign Targeting Roblox Developers via

Detection coverage for TL-2026-0845

As of 2026-06-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0845 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats