Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cybercriminals Use Fake Game Updates on Itch.io and Patreon to Push Lumma Stealer

The indie gaming community is currently facing a significant threat involving the distribution of Lumma Stealer malware via itch.io and Patreon. This malware is being disguised as legitimate game updates and is disseminated through a coordinated spam…

The indie gaming community is currently facing a significant threat involving the distribution of Lumma Stealer malware via itch.io and Patreon. This malware is being disguised as legitimate game updates and is disseminated through a coordinated spam campaign targeting users of the platform.

Newly created accounts on itch.io are posting comments on legitimate game pages, claiming to offer "game updates." These comments contain links directing users to Patreon, where archives named "Updated Version.zip" can be downloaded.

Upon extraction, these archives mostly contain benign files. However, the primary executable, "game.exe," is the actual malware payload that employs advanced evasion techniques to avoid detection.

Technical Specifications: Nexe Compilation

This campaign is notable for utilizing nexe, a compiler that converts Node.js applications into standalone PE executables. This method eliminates the need for the node.exe runtime, enhancing the malware's portability and making it harder to detect.

Decompilation reveals an obfuscated JavaScript file named "mains.js" that functions as the malware's core engine. It includes multiple anti-analysis routines designed to hinder security researchers and automated analysis systems.

The indie gaming community is currently facing a significant threat involving the distribution of Lumma Stealer malware via itch.io and Patreon.
Vanessa Ray · Thehackingpost

The malware's defensive strategy includes six distinct anti-analysis subroutines:

Checking system resources: The malware halts execution if RAM is below 4GB or CPU cores are two or fewer. Searching for sandbox usernames from a predefined list, including identities like "sandbox," "vmware," and "malware." Comparing running processes against a list of over 60 malware analysis tools, including debuggers like IDA Pro, Wireshark, and Burp Suite. Examining video controller names to identify virtualization indicators such as VMware SVGA 3D and VirtualBox graphics adapters. Checking system refresh rates, terminating if rates fall below 29Hz. Inspecting disk drive model names for virtual machine identifiers.

Once these defenses are bypassed, the malware deploys its final payload using a reflective loading technique. It decodes and writes a file named "modules.node," a DLL with Node.js API export functions, to the system's temporary directory. This DLL then loads a LummaStealer variant directly into memory using Node.js APIs.

Advertisement

Evidence suggests a single threat actor is managing this campaign across multiple itch.io accounts. Despite efforts to remove malicious accounts, new ones continue to emerge.

Users are advised to exercise caution when downloading game updates from itch.io and verify all updates through official game developer channels rather than community comments. Security teams should monitor for nexe-compiled executables and implement robust endpoint detection for the multi-layered anti-analysis techniques employed in this campaign.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories