< BACK TO NEWS
negativeSYS.SOURCE: The Hacker News2026-09-03T16:13:01+05:30

Exploitation of Node.js Runtime for Malware Delivery in Targeted Cyber Attacks

Attackers are exploiting the legitimate Node.js runtime to deploy malware via interpreted scripts, bypassing signature-based detection and using techniques like EtherHiding for persistence. The campaign involves blockchain-based C2 infrastructure and targets organizations through social engineering tactics like ClickFix.

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.

According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.

"The technique's appeal is that node.exe (the

Read original article

*** END OF TRANSMISSION ***