Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

Cybersecurity researchers have identified a new attack vector where threat actors use the legitimate Node.js runtime to deploy malware. By leveraging signed, trusted binaries, attackers are successfully bypassing traditional signature-based security detection methods.
Why it matters
This technique highlights a growing trend of 'living-off-the-land' attacks, where hackers exploit trusted software to maintain long-term access to sensitive government and corporate networks.
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.
According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.
"The technique's appeal is that node.exe (the binary that runs Node.js) is a legitimate, signed developer tool," the Broadcom-owned cybersecurity division said in a report shared with The Hacker News. "The attacker's malicious code lives in interpreted scripts rather than in a binary, making it less likely to trigger signature-based detection, while a registry Run key entry can relaunch the payload at every login."
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in