MALICIOUS (1) campaign cataloged at 2026-03-28(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-03-roboat-addition¶
During installation package downloads and runs a malicious executable. Likely continuation of 2026-03-rowrap.
The campaign is built over a malicious Roblox API wrapper. The roboat[.]pro (later robase[.]app) domain advertises a wrapper that is either directly malicious (as roboat collected in the campaign 2026-03-rowrap) or uses a malicious dependencies (like roboat-utils). New versions are published simultaneously with malicious dependencies and quickly removed. Another advertisement channel is https://github.com/Addi9000/roboat referencing two active contributors: https://github.com/Addi9000 and https://github.com/RoCruise
Abuse categories¶
clones_real_package
The package is a clone of a legitimate package or library, but with malicious code added.
malware
Package contains or installs known malware.
override_install
The package overrides the install command in setup.py to execute malicious code during installation.
remote_executable
Downloads and executes a remote executable.
through_dependency
The malicious code is intentionally included in a dependency of the package
References¶
Referenced resources may include blog posts about the campaign, malware analysis, sandbox reports, or other relevant information.
-
https://github.com/Addi9000/roboat/blob/331166c8ea3bd080f08fe6d571202e3b47017ed7/README.md#L31
-
https://github.com/Addi9000/roboat/commit/331166c8ea3bd080f08fe6d571202e3b47017ed7
IoCs & related URLs¶
URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.
-
hxxps://jolly-violet-def9.staraledreamer.workers.dev/DDDD.exe -
jolly-violet-def9.staraledreamer.workers.dev -
hxxps://holy-sun-41ff.staraledreamer.workers.dev/gore.vbs -
holy-sun-41ff.staraledreamer.workers.dev -
hxxps://github.com/betonme27/flies/releases/download/a/s22s.zhr -
hxxps://dawn-thunder-f821.staraledreamer.workers.dev/gore.vbs -
hxxps://green-shadow-38d7.aledreamsaledreams2.workers.dev/tree.vbs -
hxxps://spring-math-9df3.aledreamsaledreams2.workers.dev/winre.bat -
spring-math-9df3.aledreamsaledreams2.workers.dev -
hxxps://github.com/aledreamsaledreqms-source/frakenstein/raw/refs/heads/main/tree.vbs -
hxxps://lingering-field-4351.aledreamer1234.workers.dev/yy.bat -
hxxps://github.com/aledreamsaledreqms-source/frakenstein/raw/refs/heads/main/ee.exe -
hxxps://i-like-boys.com/tree.vbs -
i-like-boys.com
Packages in the campaign¶
campaign:2026-03-roboat-addition¶
- api-analysis
- api-feature
- bloxy-api
- database-roblox
- databaselooks
- databasenaps
- databaseroboat
- databaseroboats
- databaserobooms
- databaserotacos
- databasesupalake
- databasesupasafe
- databasetapes
- databasetrace
- pycolorlib3
- rblx-api
- robase
- robase-api
- robase-app
- robase-fallback
- robase-help
- robase-install
- robase-installer
- robase-quick-install
- robase-utils
- roboat-addition
- roboat-additions
- roboat-utilities
- roboat-utils
- roboats-addition