Luna Grabber is an open-source information-stealing malware family focused on harvesting data from local web browsers and Discord. It is part of a cluster of commodity stealers that share code and behavioral similarities with projects such as Creal Stealer, Kyoku Cookie Token Stealer, and BlackCap Grabber. The malware has been referenced as a source of reused functionality by later stealers, including Golang-based variants developed by other actors.
Luna Grabber has been observed delivered through malicious software supply-chain activity in the npm ecosystem. In one documented campaign, threat actors published multistage packages impersonating legitimate Roblox development dependencies in order to target Roblox developers and users of Node.js tooling. These packages copied functionality from legitimate libraries while adding malicious logic that executed commands, enumerated files and user information, and ultimately implanted Luna Grabber.
The malware’s primary purpose is credential and data theft. High-confidence reporting indicates it is designed to steal information from browser stores and Discord-related data on infected systems. Its codebase and operational patterns have also been cited as closely resembling other open-source stealers, particularly in blacklist and anti-analysis logic reused by related malware families. Luna Grabber is most strongly associated with Windows-centric stealer activity and developer-focused social engineering through poisoned open-source packages.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source grabber/stealer project cited for similar anti-analysis and Discord bypass logic compared with Skuld.
Mentioned as another open-source stealer with similar blacklist information to Bandit.
Open-source information-stealing malware delivered via malicious npm packages impersonating Roblox-related libraries. It steals information from the victim's local web browser, Discord application, and other local sources.
Mentioned as another stealer/grabber with similar blacklist-based evasion behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.