Infostealer Campaign Targeting Roblox Developers via Malicious 'robase' Python Package and Fake Discord Job Offers
Infostealer Campaign Targeting Roblox Developers via (TL-2026-0845), also tracked as robase campaign, is a high-severity malware campaign, first published 2026-06-17. It has no confirmed attribution, affects Roblox Corporation Roblox (developer accounts, groups, games, Robux), maps to 17 MITRE ATT&CK techniques (T1005, T1036, T1059), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-0845
- Threat ID
- TL-2026-0845
- Also known as
- robase campaign, Roblox developer infostealer campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-06-17
- Last reviewed
- 2026-06-17
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- gaming, game development, online entertainment, individual creators
- Target regions
- Global, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Infostealer Campaign Targeting Roblox Developers via
Malware and tooling: BlankGrabber, Discord Injector, Skuld
An active social-engineering campaign targets Roblox game developers with infostealer malware delivered through fake Discord project-manager job offers and studio impersonation, distributing a malicious Python package named 'robase'. The malware steals authenticated browser sessions and the .ROBLOSECURITY token to bypass two-factor authentication, enabling theft of developer accounts, group ownership, entire published games, and Robux balances.
How Infostealer Campaign Targeting Roblox Developers via works
Since at least early 2026, threat actors have been running a persistent, financially and ownership-motivated social-engineering campaign against Roblox developers. The attack begins on Discord: operators pose as recruiters or legitimate game studios (e.g., impersonating 'Cheesy Studios') and dangle a paid project-manager role. After building rapport, they ask the target to 'install a Python package' or 'run a particular file' as part of supposed internal database or project tooling. The package named in confirmed victim accounts is 'robase', described to the victim as a 'database tool'. Shortly after installation, victims are forcibly logged out of Roblox on both PC and mobile, with attackers proceeding to seize the account, the developer group, the published game(s), and any Robux balance.
The core technique is session-token / cookie theft rather than password theft. Infostealers grab the authenticated browser session and the Roblox .ROBLOSECURITY cookie (and frequently Discord tokens), which are presented directly to the platform's servers — making two-factor authentication (2FA) irrelevant because the attacker is already authenticated as the victim. This same session-hijacking pattern lets the attacker pivot across Roblox, Discord and other accounts the stealer harvests.
The 'robase' lure sits within a broader, well-documented ecosystem of supply-chain attacks on the Roblox developer community across PyPI and npm. Related campaigns have published typosquatted/impersonating packages — including npm packages node-dlls, ro.dll, autoadv and two versions of rolimons-api — that deliver the Go-based Skuld infostealer and the Python-based Blank Grabber, and PyPI packages embedding a 'Discord Injector' that exfiltrates Discord tokens and skims payment-card data. These payloads commonly pull secondary executables and tooling from the Discord CDN and GitHub, and exfiltrate harvested data over Discord webhooks. Documented victims of the current Roblox-developer wave include 'The Shadow Network' (a game built by the Matziaris brothers), a 15-year-old developer (Jovan Rai) who was earning roughly 10,000 Robux/day and needed 30+ days to recover, and developer Mohamed Kaparoza, who documented the Discord-to-robase attack chain.
Mitigation centers on treating unsolicited Discord job offers that request software installation as hostile, testing unknown packages only in isolated virtual machines, reviewing and revoking active Roblox/Discord sessions, enabling Roblox 'Enhanced Protection' / account-security features, and deploying real-time endpoint malware detection. Because the attack defeats 2FA through stolen session material, response must include immediate session revocation and credential rotation, not just a password reset.
MITRE ATT&CK techniques used in TL-2026-0845
Collection
Defense Evasion
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1102 Web Service; T1105 Ingress Tool Transfer
Initial Access
T1195 Supply Chain Compromise; T1566 Phishing
Discovery
T1217 Browser Information Discovery
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Impact
lateral-movement
T1550 Use Alternate Authentication Material
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Affected products and versions in Infostealer Campaign Targeting Roblox Developers via
- Roblox Corporation — Roblox (developer accounts, groups, games, Robux)
Vulnerable versions: accounts relying on session cookies / 2FA - Python Software Foundation — PyPI (Python Package Index)
Vulnerable versions: malicious package 'robase' - OpenJS / npm — npm registry
Vulnerable versions: node-dlls 1.0.0; ro.dll 1.0.0; autoadv 1.0.0; rolimons-api 1.1.0; rolimons-api 1.1.2 - Discord Inc. — Discord (accounts, tokens, CDN abused for delivery/exfiltration)
Vulnerable versions: session tokens - Microsoft — Windows
Vulnerable versions: systems running the infostealer payloads
Remediation for Infostealer Campaign Targeting Roblox Developers via
Immediate actions
- Treat any unsolicited Discord job/collaboration offer that asks you to install a package or run a file as malicious; do not install 'robase' or similar unverified packages
- If compromise is suspected, immediately revoke all active Roblox sessions (Settings > Security > log out of all sessions) and all Discord sessions/authorized apps — a password reset alone does NOT invalidate stolen session tokens
- Rotate the .ROBLOSECURITY token by logging out everywhere and re-authenticating, then re-enable 2FA
- Contact Roblox support to recover hijacked groups/games and document all evidence (Discord messages, screenshots, timestamps) early
Workarounds
- Disable or scope developer Discord DMs from non-contacts to reduce the social-engineering entry point
- Use separate, hardened browser profiles or accounts for Roblox development so session cookies are not co-located with general browsing
Longer-term hardening
- Only run unfamiliar packages or files inside an isolated virtual machine or sandbox, never on a machine with active Roblox/Discord sessions
- Deploy real-time EDR/anti-malware with infostealer behavioral detection on developer endpoints
- Enable Roblox Enhanced Protection / account-security features and hardware-backed or app-based 2FA
- Pin and verify dependencies; vet PyPI/npm packages (publisher, age, download count, source repo) before install and avoid typosquats
Weaknesses (CWE) in Infostealer Campaign Targeting Roblox Developers via
CWE-506, CWE-829, CWE-522, CWE-1021
Timeline of Infostealer Campaign Targeting Roblox Developers via
- Snyk and other researchers document waves of malicious PyPI packages targeting Discord and Roblox that steal credentials and payment information via an embedded 'Discord Injector', establishing the ecosystem this campaign builds on.
- Socket.dev reports malicious npm packages (node-dlls, ro.dll, autoadv, rolimons-api 1.1.0/1.1.2) impersonating Roblox developer modules to deliver Skuld infostealer and Blank Grabber; packages saw 320+ downloads before removal.
- A similar social-engineering campaign targets Roblox players with fake beta-test offers, foreshadowing the developer-focused recruitment lures.
- ThreatLocker observes the 'Powercat' campaign delivering infostealers via fake game cheat/utility software to Roblox, Minecraft, GTA V, Discord and Telegram users.
- 'The Shadow Network', a game by the Matziaris brothers, is compromised in the Roblox-developer infostealer wave.
- 404 Media reports that attackers are hijacking entire Roblox games via these infostealer-driven account takeovers.
- A 15-year-old developer (Jovan Rai) earning ~10,000 Robux/day reports 30+ days of recovery effort after account takeover; victims lose group ownership, games, and Robux balances.
- Developer Mohamed Kaparoza documents being contacted on Discord, offered a project-manager role, asked to install 'robase' described as a database tool, then logged out of Roblox on PC and phone.
- Malwarebytes publishes analysis describing the 'robase' Python-package lure delivered via fake Discord project-manager job offers and 'Cheesy Studios' impersonation, with session-token theft bypassing 2FA.
Sources cited for Infostealer Campaign Targeting Roblox Developers via
- Roblox developers are losing entire games to malware attacks
- Hackers Are Hijacking Entire Roblox Games Now
- Roblox Developers Targeted with npm Packages Infected with Infostealers
- Malicious npm Packages Target Roblox Users with Data-Stealing Malware
- Roblox and Discord Become Virus Vectors for New PyPI Malware
- Whack-a-Mole: More Malicious PyPI Packages Spring Up Targeting Discord, Roblox
- Snyk finds PyPI malware that steals Discord and Roblox credential and payment info
- From Cookies to Keys: The Threat of Session Hijacking (session-token / 2FA bypass background)
- Powercat malware campaign: Fake game cheats deliver infostealer targeting Discord, Roblox, and crypto wallets
Threats related to Infostealer Campaign Targeting Roblox Developers via
Detection coverage for TL-2026-0845
As of 2026-06-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0845 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.