cuberealm aimbot VNMLEGEN1D was reported 07-10-2026 for Obfuscated code
I am reporting this script because it appears to collect and transmit users' CubeRealm session tokens to an external server without clearly informing the user.
The script contains code that reads the `session` value from the browser's `localStorage`:
`localStorage.getItem('session')`
It then sends that value, together with the player's username, to an external `.replit.dev` server through a POST request to `/api/session`.
The script also repeats this transmission approximately every 28–32 seconds using `setInterval`, rather than only sending data once.
This is especially concerning because a session token may potentially be used to access or impersonate a user's active session. Users installing the script may therefore unknowingly expose sensitive authentication information to a third party.
The destination is constructed in the script rather than being presented transparently, which makes this behavior particularly suspicious.
I recommend investigating the script and its external endpoint, and removing or disabling it if the collection and transmission of session tokens is unauthorized.
I have not installed or executed the script myself; I inspected its source code before using it.
VNMLEGEND (the reported user) has made:
This report has been upheld by a moderator.
