The malicious actor behind noblox.js-vps took full advantage of this user-friendly evolution, using the Luna Grabber builder (Figure 4) to create the executable later served by the malicious packages.
The current npm campaign seems focused on harvesting system information from victims, employing a configurable builder provided by the authors of Luna Token Grabber. This restraint might suggest that the threat actor behind the campaign has chosen not to escalate the attack to more damaging stages, but the potential consequences remain concerning for Roblox developers.