- Threat actors are abusing the trusted, signed Node.js runtime to deploy malicious payloads, evading signature-based detection.
- Campaigns since February 2026 have targeted government departments, technology companies, and hotels via the ClickFix social engineering technique.
- Attackers use the Polygon cryptocurrency blockchain as a dynamically updatable address book for command-and-control servers, making takedowns ineffective.
- Multiple threat groups, including the initial-access broker KongTuke, employ tools like AsukaStealer, C2Looper, and EtherHiding alongside Node.js.
- At least 31 organizations have been compromised through fake CAPTCHA prompts that deploy persistent backdoors.
Threat actors have been leveraging the legitimate Node.js JavaScript runtime to deploy malicious payloads in attacks targeting government departments, technology companies, and hotels since February 2026, according to a report from the Symantec Threat Hunter Team. The attackers use node.exe—a signed developer tool—to run interpreted scripts, making the activity less likely to trigger signature-based detection while a registry Run key re-launches the payload at each login.
In one intrusion observed between March and July 2026 against an Asian technology firm, attackers downloaded Node.js from the official site and used it to deploy a malicious implant that retrieves commands via EtherHiding. The same method has been paired with ModeloRAT and Mistic (aka MLTBackdoor), tools attributed to the initial-access broker KongTuke, who also uses a malicious Chrome extension named NexShield in a ClickFix variant called CrashFix.
Meanwhile, a separate campaign identified by GuidePoint Security compromised at least 31 organizations—including e-commerce, professional services, and retail logistics businesses—through fake CAPTCHA prompts that deploy a persistent backdoor. “This campaign sidesteps that defense by using the Polygon cryptocurrency blockchain as a dynamically updatable address book,” researcher Jean-Pierre Mouton said. For fractions of a cent per transaction, attackers can redirect every infected machine to a new C2 server automatically, neutralizing traditional blocking methods.
The technique has also been observed against a U.S. fintech organization, where attackers deployed C2Looper, a Rust-based backdoor documented by Zscaler ThreatLabz. Symantec noted that multiple threat actors of varying skill levels are now exploiting Node.js, using combinations of living-off-the-land tools, commodity malware, and new implants like Backdoor.Mistic and a fresh version of AsukaStealer. Organizations are advised to audit public-facing websites for suspicious changes, restrict unapproved browser extensions, and train employees to recognize ClickFix-style social engineering.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
