Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Symantec reports threat actors weaponising the trusted Node.js runtime for payload delivery against government and enterprise targets — a living-off-the-land technique that evades application whitelisting by hiding in legitimate process trees.
Summary written by editorial AI · Source link below
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.
According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.
"The technique's appeal is that node.exe (the
Editorial Analysis
Trusted runtimes like Node.js present on enterprise systems become invisible malware delivery vehicles, undermining application control strategies.
Audit Node.js installations across non-development systems and implement execution monitoring for unexpected runtime invocations.
Attackers are using the trusted Node.js runtime already installed on enterprise systems to deliver malware undetected by conventional security controls.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d