Node.js Abuse Signals Shift in Malware Delivery
Threat actors are hijacking the trusted Node.js runtime to deliver malware, evading detection in targeted attacks since early 2026.
The trusted Node.js JavaScript runtime has become a favored tool for threat actors seeking to slip malicious code past security defenses. According to a report from Symantec's Threat Hunter Team, attackers have been abusing this legitimate, signed developer tool since February 2026, turning a widely trusted binary into a vehicle for implanting backdoors and other payloads in targeted environments.
Why Attackers Are Turning to Node.js
Symantec, the cybersecurity arm of Broadcom, explained that the appeal lies in the binary itself. "The technique's appeal is that node.exe (the binary that runs Node.js) is a legitimate, signed developer tool," the company noted. Because the malicious payload lives in interpreted scripts rather than in a compiled binary, it is far less likely to trigger signature-based detection systems. Further, a registry Run key entry can relaunch the payload at each login, ensuring persistence on compromised systems.
This approach has been observed in attacks targeting government departments, technology firms, and hotels since February 2026. The report, shared with The Hacker News, details how the method has enabled attackers to maintain long-term access and retrieve commands using a technique called EtherHiding.
A Case Study in Asia
One intrusion stood out in the report, occurring between March 23 and July 25, 2026, against an Asian technology company. The attackers downloaded the official Node.js installer from nodejs[.]org, leveraging the signed runtime to deploy a malicious implant. This implant established a persistent foothold and allowed the attackers to pull commands and additional tooling through EtherHiding, a method that uses blockchain infrastructure to obscure communication.
Symantec noted that the shift to Node.js came after the attackers' repeated attempts to deploy AdaptixC2 and Cobalt Strike beacons were blocked. These initial attempts followed obtaining access through ClickFix, a social engineering technique that tricks users into running malicious commands under the guise of fixing a problem or verifying they are not bots.
Links to Known Initial Access Brokers
The technique has also been paired with ModeloRAT and Mistic (also known as MLTBackdoor), both attributed by Symantec to an initial access broker named KongTuke, or Woodgnat. In June 2026, Symantec detailed how Woodgnat attack chains abuse "node.exe" to run attacker-controlled JavaScript, chaining PowerShell and Windows command-line tools together. The same operation also involved a malicious Chrome extension called NexShield, part of a ClickFix variant dubbed CrashFix.
Another payload used in these attacks is a .NET tool named GateKeeper, which features layered encryption and victim-fingerprinting logic. The reuse of these techniques and tools suggests a coordinated approach among threat actors with access to similar resources.
Incident at a U.S. Fintech Firm
A similar pattern emerged against a U.S. fintech organization. There, the attackers used their ClickFix foothold to deploy an AdaptixC2 agent and a Cobalt Strike Beacon. The earliest observed activity took place on May 6, 2026. More than two months later, the attackers installed C2Looper, a Rust-based backdoor documented by Zscaler ThreatLabz last month.
Symantec found no evidence that the threat actors engaged in credential theft, lateral movement, or destructive operations in this incident. It remains unclear whether they achieved their end goals beyond establishing a foothold with the backdoor.
"While the use of node.js and connection to the Ethereum blockchain wasn't observed in that incident, shared domains and similarities in the attack chain point to the same attackers being behind the activity," Symantec said. "It's likely we didn't see Node.js activity on this organization because the attackers were able to successfully deploy a backdoor."
This quote from the Symantec Threat Hunter Team highlights the adaptive nature of these campaigns. The attackers chose the most effective tool available to them, and when Node.js was unnecessary, they skipped it in favor of a more direct route.
A Growing Arsenal of Node.js Malware
The scope of Node.js abuse extends beyond these two cases. Symantec said multiple threat actors are now using the runtime in their operations. Tools observed in these attacks include a Node.js version of an information stealer named AsukaStealer, EtherRAT, and an assortment of legitimate Microsoft and command-line utilities used for living-off-the-land techniques.
This mixture of dual-use tools and commodity malware indicates that Node.js is being adopted by a broad range of actors. As Symantec concluded, "Attackers using Node.js appear happy to use a combination of both living-off-the-land and dual-use tools in their attacks, as well as commodity malware, and new tools such as Backdoor.Mistic, C2Looper, and the new version of AsukaStealer."
"This indicates that attackers with a variety of skill levels may be using Node.js as it has returned to popularity," the report added.
ClickFix Campaign Hits Dozens of Firms
The report lands alongside a separate disclosure from GuidePoint Security, which found that attackers have compromised at least 31 organizations, including e-commerce, professional services, and retail logistics businesses. This ClickFix campaign serves fake CAPTCHA verification prompts to visitors on compromised sites, deploying a persistent backdoor that abuses EtherHiding to locate command-and-control (C2) infrastructure and receive commands.
GuidePoint Security researcher Jean-Pierre Mouton explained the novelty of the C2 approach.
"Traditionally, ClickFix malware can be neutralized by blocking the attacker's C2 server, cutting off communications with infected machines," Mouton said. "This campaign sidesteps that defense by using the Polygon cryptocurrency blockchain as a dynamically updatable address book."
"Because it allows for ad hoc adjustment of C2 details at scale, blocking a singular domain or IP address alone does not permanently sever attacker access. For fractions of a cent per transaction, the attacker can redirect every infected machine to a new C2 server automatically."
Users are lured into copying a command presented in the CAPTCHA-like prompt and pasting it into the Windows Run dialog or Windows Terminal, which compromises their own systems. Over the past two years, ClickFix and its variants have risen sharply in popularity, exploiting the tendency of users to follow instructions when presented with a plausible error or bot-check.
Guarding Against the Next Wave
For organizations, the report outlines several steps to mitigate these threats. Continuous auditing of public-facing websites for suspicious changes or malicious scripts is a first line of defense. Restricting unapproved browser extensions can limit an attacker's ability to pivot from a compromised site to a local system. Finally, security awareness training focused on recognizing ClickFix-style social engineering tactics can help employees avoid the initial mistake that leads to an infection.
The shift toward Node.js as a delivery vehicle shows how attackers keep pace with trust. As more organizations rely on legitimate development tools, the line between routine software and malicious payloads becomes harder to spot.
Sources
- The Hacker News Original source
Continue Reading
RMM Phishing Campaign Zeroes In on US Targets
A phishing campaign spanning 46 countries uses fake documents to push RMM tools, with 45% of activity aimed at the US.
FBI Opens Probe Into License Data Sale
A dark web service is selling 153M+ driver's license images, prompting an FBI inquiry.
Ransom Refusal Exposes 8.8M in Airport Breach
Manchester Airports Group data leak exposes 8.8M records after refusing ransom.