BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Attackers Leverage Node.js to Deploy Malicious Payloads

Attackers abuse signed Node.js and Polygon blockchain to deploy backdoors via fake CAPTCHA prompts.

  • Threat actors are abusing the trusted, signed Node.js runtime to deploy malicious payloads, evading signature-based detection.
  • Campaigns since February 2026 have targeted government departments, technology companies, and hotels via the ClickFix social engineering technique.
  • Attackers use the Polygon cryptocurrency blockchain as a dynamically updatable address book for command-and-control servers, making takedowns ineffective.
  • Multiple threat groups, including the initial-access broker KongTuke, employ tools like AsukaStealer, C2Looper, and EtherHiding alongside Node.js.
  • At least 31 organizations have been compromised through fake CAPTCHA prompts that deploy persistent backdoors.

Threat actors have been leveraging the legitimate Node.js JavaScript runtime to deploy malicious payloads in attacks targeting government departments, technology companies, and hotels since February 2026, according to a report from the Symantec Threat Hunter Team. The attackers use node.exe—a signed developer tool—to run interpreted scripts, making the activity less likely to trigger signature-based detection while a registry Run key re-launches the payload at each login.

- Advertisement -

In one intrusion observed between March and July 2026 against an Asian technology firm, attackers downloaded Node.js from the official site and used it to deploy a malicious implant that retrieves commands via EtherHiding. The same method has been paired with ModeloRAT and Mistic (aka MLTBackdoor), tools attributed to the initial-access broker KongTuke, who also uses a malicious Chrome extension named NexShield in a ClickFix variant called CrashFix.

Meanwhile, a separate campaign identified by GuidePoint Security compromised at least 31 organizations—including e-commerce, professional services, and retail logistics businesses—through fake CAPTCHA prompts that deploy a persistent backdoor. “This campaign sidesteps that defense by using the Polygon cryptocurrency blockchain as a dynamically updatable address book,” researcher Jean-Pierre Mouton said. For fractions of a cent per transaction, attackers can redirect every infected machine to a new C2 server automatically, neutralizing traditional blocking methods.

The technique has also been observed against a U.S. fintech organization, where attackers deployed C2Looper, a Rust-based backdoor documented by Zscaler ThreatLabz. Symantec noted that multiple threat actors of varying skill levels are now exploiting Node.js, using combinations of living-off-the-land tools, commodity malware, and new implants like Backdoor.Mistic and a fresh version of AsukaStealer. Organizations are advised to audit public-facing websites for suspicious changes, restrict unapproved browser extensions, and train employees to recognize ClickFix-style social engineering.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Micron stock all-time high talk grows pre Sept. 30 earnings

Micron shares trade near $980, over 20% below the June 2026 closing record of...

Pencil Finance completes $1M on-chain student loan cycle

Pencil Finance completed a $1 million student-loan cycle fully on-chain, from investor capital to...

Bitcoin Trades More Like Gold, Bolstering Digital Gold Case

Bitcoin's 90-day correlation with Gold climbed to its highest level since 2020, while its...

Orionx shuts after $7M custody loss, blames co-founders

Chilean crypto exchange Orionx is shutting down after a forensic audit discovered over $7...

MikroTik SSH exploit grants full admin control without auth

Attackers are exploiting a critical vulnerability in MikroTik RouterOS that grants full administrative control...

Must Read

How Cryptocurrency Works For Beginners?

Welcome to the world of cryptocurrency! If you're new to this exciting and rapidly evolving landscape, you might feel like Alice in Wonderland, exploring...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading