LTX Stealer is a Windows information stealer that targets browser credentials, authenticated sessions, and cryptocurrency-related data. Publicly observed in early 2026, it is marketed through LTX Public as a commercial stealer-as-a-service offering with weekly and monthly subscriptions.
The malware is distributed through a heavily obfuscated Inno Setup installer containing a large, predominantly encrypted archive. The installer requests administrator privileges and deploys a payload that impersonates a Microsoft updater, marking its installation directory and executable with Hidden and System attributes. The payload uses pkg to bundle JavaScript, dependencies, and a full Node.js runtime into a standalone executable. Bytenode-compiled JavaScript bytecode adds another layer of resistance to static analysis and source recovery.
LTX Stealer targets Chromium-based browsers, including Google Chrome and Microsoft Edge, to recover saved usernames and passwords, cookies, authentication tokens, and active session data. A Python helper enables debug privileges, duplicates an LSASS token, and impersonates SYSTEM to perform browser-key decryption under both SYSTEM and user contexts. This process recovers Chromium app-bound encryption material and derives the browser master key needed to decrypt protected data.
The malware also searches for cryptocurrency wallet files and browser-wallet extension data, captures screenshots, and collects system information. It queries an external geolocation service to identify the victim's country, region, and internet service provider. Collected material is staged locally and compressed into archives for exfiltration to attacker-controlled infrastructure. Its operator infrastructure uses Cloudflare to obscure backend hosting and Supabase for panel authentication and access control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
"hosting payloads on trusted cloud services such as Google Drive and OneDrive"; "retrieve next-stage shellcode payloads... hosted on trusted platforms like Cloudflare Pages, Netlify, and Discord"; "Cloudflare is leveraged to front backend services and mask infrastructure details"
The installer contents revealed an unusually large, embedded archive containing 5,888 files, of which 5,881 were encrypted.
The payload was built using pkg, which bundles JavaScript code, application dependencies, and the Node.js runtime into a single executable.
LTX Stealer follows this pattern by leveraging Inno Setup as its initial delivery mechanism, embedding encrypted payloads that are only decrypted at runtime.
"The infection begins with a file named Negro.exe, which presents itself as a standard Windows application. However, under the hood, it is a Trojan horse. The malware utilizes Inno Setup... to blend in with legitimate software distribution workflows."
"...allowing it to recover saved passwords, cookies, and active session tokens."
All collected cryptocurrency artifacts are aggregated alongside browser credentials, screenshots, and system information.
"The malware connects to a backend infrastructure powered by Supabase and fronted by Cloudflare, mimicking a professional SaaS application."
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Node.js-based Windows information stealer distributed via an obfuscated Inno Setup installer; harvests credentials from Chromium browsers and targets cryptocurrency artifacts, staging data for exfiltration using cloud-backed infrastructure.
Node.js-based Windows information stealer that harvests credentials from Chromium browsers and targets cryptocurrency artifacts, staging data for exfiltration using cloud-backed infrastructure.
Windows infostealer delivered via an obfuscated Inno Setup-based installer that embeds a full Node.js runtime and uses JavaScript bytecode compilation to hinder analysis. It steals Chromium browser data (passwords, cookies, session tokens) by leveraging Chromium decryption logic (via a decrypt.py script) and also searches for cryptocurrency wallet-related files/extensions. Operates as a Stealer-as-a-Service with backend infrastructure using Supabase and Cloudflare.
Windows infostealer that embeds a full Node.js runtime to execute.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.