The record
Written from the 1 report below. Nothing here is unsourced.
- Cyber attackers are using the legitimate, widely trusted Node.js runtime to run malicious scripts and install backdoors in targeted attacks.
- Symantec reports the technique has been used since February 2026 against government departments, technology companies, and hotels.
- The malware hides in scripts run by the signed node.exe tool rather than a suspicious binary, helping it evade signature-based antivirus detection.
- A related ClickFix campaign, tracked by GuidePoint Security, has compromised at least 31 organizations and uses blockchain networks to hide its command-and-control addresses, making blocklists less effective.
- Organizations are advised to audit public-facing websites, restrict unapproved browser extensions, and train employees to spot ClickFix-style prompts.
What to watch next
- Whether more threat groups adopt Node.js abuse as its popularity among attackers grows.
- Effectiveness of blockchain-based C2 in resisting traditional domain or IP blocklist defenses.
- Further Symantec or vendor disclosures identifying victims or new malware families linked to these chains.
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Symantec
cybersecurity company owned by Broadcom
1 quote · 1 outlet
“The technique's appeal is that node.exe (the binary that runs Node.js) is a legitimate, signed developer tool”
In the article
…According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. " The technique's appeal is that node.exe (the binary that runs Node.js) is a legitimate, signed developer tool ," the Broadcom-owned cybersecurity division said in a report shared with The Hacker News. "The attacker's malicious code lives in interpreted scripts rather than in a binary, making it less likely to trigger…
Coverage1
All filed from India
Named United States · AdaptixC2 · AsukaStealer · Broadcom · Cobalt Strike · EtherRAT · Mistic · ModeloRAT · NexShield · Node.js · GuidePoint Security · Jean-Pierre Mouton · KongTuke
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
