Node Js Runtime Abuse Linked To Malware Campaigns Targeting Multiple Sectors

Node Js Runtime Abuse Linked To Malware Campaigns Targeting Multiple Sectors

Threat actors are increasingly abusing the trusted Node.js JavaScript runtime to deploy malicious payloads in targeted cyber attacks, according to a new report from Symantec’s Threat Hunter Team. Researchers said the technique has been observed in attacks against government departments, technology companies, hotels, and financial organizations since February 2026. Rather than relying on traditional malware binaries, attackers download the legitimate Node.js installer from the official website and use the signed node.exe runtime to execute malicious JavaScript. Because the code is interpreted instead of compiled into an executable file, it is less likely to be detected by signature based security tools. Researchers also noted that attackers establish persistence by creating a Windows registry Run key, allowing the malicious payload to relaunch whenever a user logs into the compromised system.

Symantec documented one intrusion targeting an unnamed technology company in Asia between March 23 and July 25, 2026. During the attack, threat actors downloaded the official Node.js installer and used the trusted runtime to deploy a malicious implant capable of maintaining long term access and retrieving additional commands through the EtherHiding technique. Researchers said the attackers adopted this method after multiple attempts to deploy AdaptixC2 and Cobalt Strike beacons were blocked following initial access gained through the ClickFix social engineering technique. The report also links similar activity to attacks involving ModeloRAT and Mistic, also known as MLTBackdoor, which have been associated with an initial access broker tracked as KongTuke, also referred to as Woodgnat. Earlier research showed that these attack chains used node.exe to execute malicious JavaScript alongside PowerShell commands, Windows command line utilities, a malicious Chrome extension named NexShield delivered through a ClickFix variant called CrashFix, and a .NET payload known as GateKeeper featuring layered encryption and victim fingerprinting capabilities.

Researchers observed a similar attack pattern against a United States financial technology organization, where attackers used ClickFix to gain initial access before deploying an AdaptixC2 agent and a Cobalt Strike Beacon. More than two months later, the attackers installed a Rust based backdoor called C2Looper. While investigators found no evidence of credential theft, lateral movement, or destructive activity, the backdoor successfully established a persistent foothold within the environment. Symantec noted that although Node.js and Ethereum blockchain communication were not identified during that particular incident, similarities in infrastructure and attack techniques suggest the same threat actors were responsible. The company added that the absence of Node.js activity may indicate the attackers achieved their objective by successfully deploying another backdoor. The report also highlights the use of additional malware families, including the Node.js version of AsukaStealer, EtherRAT, and various legitimate Microsoft and Windows command line tools, demonstrating that attackers with different levels of technical capability are adopting Node.js as part of their operations.

The findings come as GuidePoint Security disclosed a separate ClickFix campaign that has affected at least 31 organizations across industries including electronic commerce, professional services, and retail logistics. According to the report, attackers compromised legitimate websites by injecting fake CAPTCHA verification prompts that trick visitors into executing malicious commands. The campaign uses EtherHiding to obtain command and control information through the Polygon blockchain, allowing operators to update infrastructure without relying on fixed domains or IP addresses. Researchers explained that this approach makes traditional blocking methods less effective because attackers can redirect infected systems to new command servers with minimal cost. Security experts recommend that organizations continuously monitor public facing websites for unauthorized modifications, restrict unapproved browser extensions, and strengthen employee awareness training to help users identify ClickFix style social engineering attempts before they compromise their systems.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment