Attackers Abuse Node.js to Deliver Malware

Attackers are abusing the trusted Node.js runtime to deliver malware and evade detection in targeted attacks on organizations.
Cybercriminals are increasingly abusing the legitimate Node.js JavaScript runtime as a way to deliver malware and maintain access to compromised systems, according to new research from Symantec’s Threat Hunter Team. The technique has been observed in attacks against government departments, technology companies and hotels since February 2026.
Rather than relying entirely on conventional malware executables, attackers use the legitimate node.exe binary to run malicious JavaScript. Because Node.js is a trusted, digitally signed developer tool, its presence on a system may not immediately raise suspicion.
Symantec said the technique is attractive to attackers because malicious code can be placed inside interpreted scripts instead of a standalone executable. The approach can make traditional signature-based detection more difficult. Attackers have also used Windows Registry Run keys to ensure malicious code is launched again when a victim logs in.
In one intrusion targeting an Asian technology company, attackers downloaded the official Node.js installer directly from the Node.js website. The activity occurred between March 23 and July 25, 2026. Once installed, the legitimate runtime was used to deploy a malicious implant designed to maintain long-term access and retrieve commands or additional tools.
The attackers had initially attempted to deploy AdaptixC2 and Cobalt Strike beacons, but those efforts were blocked after the attackers gained their initial foothold through a ClickFix social-engineering attack. ClickFix campaigns typically trick victims into running commands on their own computers.
Attackers often present a fake CAPTCHA, browser error or similar prompt and instruct users to copy and paste a command into Windows Run or Windows Terminal. Once the victim follows the instructions, the attacker gains an initial foothold that can be used to deploy additional tools.
In the incidents examined by Symantec, Node.js provided another way to execute malicious code after that initial compromise. Symantec also linked the Node.js technique to activity associated with an initial access broker known as KongTuke, also referred to as Woodgnat. The same attackers have been associated with ModeloRAT and Mistic, also known as MLTBackdoor.
Symantec previously reported that Woodgnat-related attacks abused node.exe to execute JavaScript and then chain together PowerShell and Windows command-line tools. Those attacks have also involved a malicious Chrome extension called NexShield, which was deployed as part of a ClickFix variant known as CrashFix.
Another component identified in the activity is GateKeeper, a .NET payload containing layered encryption and victim-fingerprinting capabilities.
A similar attack chain was observed against a U.S. fintech company. In that case, attackers initially gained access through ClickFix and attempted to deploy AdaptixC2 and Cobalt Strike. The activity eventually led to the deployment of C2Looper, a Rust-based backdoor.
The earliest activity was recorded on May 6, 2026, while the C2Looper deployment occurred more than two months later.
Symantec said it found no evidence that the attackers carried out credential theft, lateral movement or destructive activity against that organization. It also remains unclear whether they achieved their ultimate objectives beyond establishing access through the backdoor. Node.js abuse is not limited to one group or campaign.
Symantec identified several tools being used alongside the runtime, including a Node.js version of AsukaStealer, EtherRAT and various legitimate Microsoft and command-line utilities.
The security company said the combination of legitimate tools, dual-use software and conventional malware demonstrates how attackers are increasingly mixing different techniques depending on what works against a particular target.
Node.js can be particularly useful in these situations because organizations may already have legitimate development environments where the runtime is expected to exist.
The attacks also demonstrate how criminals are combining Node.js with EtherHiding, a technique that uses blockchain infrastructure to store or retrieve information associated with command-and-control operations.
A separate ClickFix campaign tracked by GuidePoint Security compromised at least 31 organizations, including businesses in e-commerce, professional services and retail logistics. In that campaign, compromised websites were used to display fake CAPTCHA prompts to visitors. Victims who followed the instructions could end up executing malicious commands on their own systems.
The campaign used the Polygon blockchain as a dynamically changeable source for command-and-control information. This approach makes traditional blocking methods less effective because attackers can change the underlying C2 infrastructure without relying on a single fixed server.
The growing use of Node.js in attacks highlights a broader security problem: legitimate software can become dangerous when attackers use it for purposes its developers never intended.
Organizations are advised to monitor public-facing websites for unauthorized modifications and malicious scripts, restrict unapproved browser extensions and train employees to recognize ClickFix-style social-engineering attempts.
The increasing combination of trusted software, legitimate administrative tools and commodity malware means defenders cannot rely solely on blocking known malicious executables. Instead, unusual use of otherwise legitimate tools and suspicious command execution may provide important clues that an attacker has gained access.
Symantec‘s findings suggest Node.js is becoming another tool in the attacker’s arsenal, not because the runtime itself is malicious, but because its legitimate status can help attackers blend their activity into normal system behavior.
Source: The Hacker News
References in this story
- KongTuke | Red Canary Threat Detection Report redcanary.com A malicious traffic distribution system, KongTuke uses compromised WordPress sites to deliver ever-evolving lures to unsuspecting users.
- Polygon | The Go-To Blockchain for Global Payments polygon.technology Polygon is the blockchain enterprises and institutions choose to move money instantly at scale — low fees, enterprise tooling, and proven reliability.
- Symantec™ Enterprise Cloud Cyber Security www.broadcom.com To meet today's Cyber Security challenges, enterprises need an integrated cyber defense platform that integrates industry-leading solutions and solves for the most pressing C-level challenges like evolving threats…
- Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks thehackernews.com Attackers abuse Node.js to execute malicious scripts and deploy payloads in attacks targeting governments, technology companies, and hotels.



