HackMyIP
← Back to News
2026-09-03 The Hacker News

Node.js Runtime Weaponized for Stealth Malware Delivery in Targeted Attacks

MalwareAPTThreat Intel

Threat actors are increasingly abusing the trusted Node.js JavaScript runtime as a covert malware delivery mechanism, targeting government departments, technology firms, and hotels in campaigns dating back to February 2026. According to the Symantec Threat Hunter Team, attackers are leveraging node.exe, a legitimate, signed developer binary, to execute malicious JavaScript that blends in with normal development activity. Because the malicious code lives in interpreted scripts rather than compiled binaries, it largely evades signature-based detection, while a simple Windows Registry Run key ensures persistence across reboots.

In one intrusion targeting an Asian technology company between March 23 and July 25, 2026, the attackers downloaded the official Node.js installer from nodejs[.]org after gaining initial access through the ClickFix social engineering technique. Repeated attempts to deploy AdaptixC2 and Cobalt Strike beacons were blocked, prompting the shift to Node.js-based payload delivery. The implant used EtherHiding, a technique that retrieves commands and tooling from the Ethereum blockchain, making network takedowns significantly harder. Researchers noted the same modus operandi appeared against a U.S. fintech organization, where it ultimately paved the way for C2Looper, a Rust-based backdoor previously documented by Zscaler ThreatLabz.

The campaigns are tied to an initial access broker tracked as KongTuke (aka Woodgnat), whose toolset includes the ModeloRAT and Mistic (MLTBackdoor) malware families, a .NET payload called GateKeeper with layered encryption and victim-fingerprinting logic, and a malicious Chrome extension named NexShield used in a ClickFix variant dubbed CrashFix. Security teams are advised to monitor for unexpected node.exe executions, audit Registry Run key entries, and scrutinize outbound traffic to blockchain nodes. Defenders investigating suspicious activity can use a WHOIS lookup to vet domains associated with these campaigns, run a port scanner to identify rogue listeners on compromised endpoints, and check C2 infrastructure with the SSL/TLS checker to validate certificate legitimacy on attacker-controlled hosts.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →