
Menace actors are leveraging the trusted Node.js JavaScript runtime in a number of cyber assaults as a approach to deploy malicious payloads.
In keeping with a brand new report printed by the Symantec Menace Hunter Staff right now, the assault methodology has been put to make use of in assaults focusing on authorities departments, expertise firms, and accommodations since February 2026.
“The approach’s enchantment is that node.exe (the binary that runs Node.js) is a reliable, signed developer device,” the Broadcom-owned cybersecurity division stated in a report shared with The Hacker Information. “The attacker’s malicious code lives in interpreted scripts quite than in a binary, making it much less prone to set off signature-based detection, whereas a registry Run key entry can relaunch the payload at each login.”
In a single intrusion noticed between March 23 and July 25, 2026, focusing on an unspecified Asian expertise firm, attackers downloaded the official Node.js installer from nodejs[.]org and used the trusted, signed runtime to deploy a malicious implant to determine long-term entry and retrieve instructions or tooling utilizing a method known as EtherHiding.
The risk actors are stated to have shifted to this strategy after their repeated makes an attempt to deploy AdaptixC2 and Cobalt Strike beacons on the sufferer’s community have been blocked after acquiring preliminary entry by way of the ClickFix social engineering approach.
Apparently, the approach has additionally been employed alongside ModeloRAT and Mistic (aka MLTBackdoor), each of that are assessed to be the work of an preliminary entry dealer named KongTuke (aka Woodgnat).
In June 2026, Symantec disclosed that Woodgnat assault chains are characterised by the abuse of “node.exe” to execute attacker JavaScript and chain PowerShell and Home windows command-line instruments, in addition to a malicious Chrome extension named NexShield as a part of a ClickFix variant dubbed CrashFix. One other device put to make use of in these assaults is a .NET payload referred to as GateKeeper that options layered encryption and victim-fingerprinting logic.
The identical modus operandi has been noticed in opposition to a U.S. fintech group, with the assault paving the way in which for the deployment of C2Looper, a Rust-based backdoor documented by Zscaler ThreatLabz final month. The earliest noticed exercise occurred on Might 6, 2026, when the attackers exploited the foothold gained by way of ClickFix to deploy an AdaptixC2 agent and a Cobalt Strike Beacon.
It is price noting that the set up of C2Looper happened greater than two months after the preliminary occasions, though there isn’t any proof that the risk actors engaged in credential theft, lateral motion, or damaging operations. It is also unclear in the event that they achieved their finish objectives past establishing the foothold utilizing the backdoor.
“Whereas the usage of node.js and connection to the Ethereum blockchain wasn’t noticed in that incident, shared domains and similarities within the assault chain level to the identical attackers being behind the exercise,” Symantec stated. “It is probably we did not see Node.js exercise on this group as a result of the attackers have been capable of efficiently deploy a backdoor.”
The cybersecurity firm stated a number of risk actors are exploiting Node.js in assaults. A number of the instruments utilized in these intrusions embrace a Node.js model of an data stealer named AsukaStealer, EtherRAT, and different reliable Microsoft and command-line utilities.
“Attackers utilizing Node.js seem completely satisfied to make use of a mix of each living-off-the-land and dual-use instruments of their assaults, in addition to commodity malware, and new instruments corresponding to Backdoor.Mistic, C2Looper, and the brand new model of AsukaStealer,” Symantec concluded. “This means that attackers with quite a lot of ability ranges could also be utilizing Node.js because it has returned to reputation.”
The disclosure comes as GuidePoint Safety stated attackers have compromised a minimum of 31 organizations, together with e-commerce, skilled providers, and retail logistics companies, by way of a ClickFix marketing campaign that serves pretend CAPTCHA verification prompts to guests arriving on the compromised websites and deploys a persistent backdoor that abuses EtherHiding to find its command-and-control (C2) infrastructure and obtain instructions.
The marketing campaign is two-pronged in that it yields two completely different sufferer varieties: the reliable enterprise whose web site is injected to show the ClickFix lure and unsuspecting customers who land on these websites.
“Historically, ClickFix malware could be neutralized by blocking the attacker’s C2 server, reducing off communications with contaminated machines,” GuidePoint Safety researcher Jean-Pierre Mouton stated. “This marketing campaign sidesteps that protection by utilizing the Polygon cryptocurrency blockchain as a dynamically updatable handle ebook.”
“As a result of it permits for advert hoc adjustment of C2 particulars at scale, blocking a singular area or IP handle alone doesn’t completely sever attacker entry. For fractions of a cent per transaction, the attacker can redirect each contaminated machine to a brand new C2 server mechanically.”
Over the previous two years, ClickFix and its quite a few variants have taken off in an enormous manner as they purpose to trick customers into performing undesirable actions underneath the pretext of fixing an error or proving they aren’t bots by copying a command introduced within the lure and pasting it onto the Home windows Run dialog or the Home windows Terminal app, successfully compromising their very own methods within the course of.
To fight the risk and others prefer it, organizations are advisable to audit public-facing web sites constantly for suspicious modifications or malicious scripts, limit unapproved browser extensions, and introduce safety consciousness coaching to assist staff acknowledge ClickFix-style social engineering ways.

