A new, fully featured Lucid Stealer build that combines large-scale credential theft with hidden remote access.
The sample, distributed through Telegram-linked underground channels, is not a simple packed executable but a Lucid-branded information stealer and RAT wrapped inside a legitimate Node.js Single Executable Application (SEA).
Static analysis recovered an embedded JavaScript loader and decrypted core payload without executing the sample, giving high confidence in the findings and a clear view of operator capabilities and infrastructure.
The malware arrives in a password-protected WinZip-AES archive containing a roughly 100 MB Windows x64 Node.js SEA executable.
Inside that runtime sits an approximately 8.5 MB NODE_SEA_BLOB JavaScript loader which rebuilds and writes helper binaries to disk, then decrypts and executes a second-stage JavaScript payload.
The recovered core uses an RC4-style PRGA and an XOR pass to protect its code.
Analysts extracted modular components responsible for browser credential and cookie theft, Discord token harvesting and injection, multiple wallet-targeting routines, keylogging, screenshot capture, remote shell and file-manager functions, DDoS commands, and HVNC-style hidden desktop control.
A bundled SQLite CLI for querying copied browser databases, a native elevation addon invoked for privilege escalation attempts, an HVNC addon for hidden VNC and remote-screen control, RobotJS for synthetic input and screen capture, and a canvas image module for rendering screenshots and streams.
Foresiet Threat Intel Team identified and statically analyzed a newly observed Lucid Stealer build promoted through Telegram-linked underground channels.
The SEA wrapper’s role is concealment and delivery; the actual risk comes from the staged helpers, the decoded configuration, and the payload’s broad command surface.
Lucid Stealer Hits 18 Browsers
Operator activity and infrastructure evidence point to a small but organized commercial operation. Foresiet correlated Telegram announcements, a hosted multi-tenant web control panel, and a release timeline showing a brief pause and rapid relaunch in late May 2026.

The operator publicly signaled plans to re-platform from Node.js to Java to evade defenses and improve performance, indicating active maintenance and likely future variations.
Screenshots of the panel and channel were sanitized for public sharing; embedded strings and loader variables include Lucid branding (for example, LUCIDPay and _LUCID*), which the report treats as operator self-identification rather than a community-assigned family name.
From a defender’s perspective, Lucid Stealer should be treated as a full compromise event. This build targets a wide array of applications 18 browsers, multiple wallet formats and extensions, and four Discord client variants so stolen browser tokens, saved passwords, Discord sessions, game sessions, and wallet seed material must be assumed exposed if execution occurred.

Because the operator is actively developing the product, static hashes identify only this specific build; reliable detection requires hunting for behavioral staging and persistence patterns instead.
High-value signals include temporary self-copies named like winupd, HKCU Run persistence entries, user-profile .node addon staging, suspicious browser database access, and the specific upload/log URI sequences recovered from the decoded configuration.
Foresiet’s blog reframes the full technical report into a corporate-style deep dive covering executive summary, threat context, technical findings, capability analysis, infection-flow details and pragmatic detection and response guidance.
Enterprises should prioritize containment, assume credential and key compromise on suspected hosts, and hunt for the staging behaviors and native helper artifacts documented in the report.
For teams wanting the full technical indicators, sanitized screenshots, hashes, and network indicators, consult the Foresiet detailed report and use behavior-focused detection rules rather than relying solely on changing file hashes.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





