BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Stealit Malware Abuses Node.js SEA to Spread Ransomware

Stealit Malware Campaign Exploits Node.js SEA Feature to Spread Subscription-Based Remote Access Trojan on Windows and Android

  • A Malware campaign named Stealit uses Node.js’ Single Executable Application (SEA) feature to spread its harmful software.
  • Stealit is distributed through fake game and VPN installers posted on file-sharing platforms like Mediafire and Discord.
  • The malware includes a remote access trojan rental service targeting Windows and Android systems with various subscription options.
  • Stealit installs multiple components that steal data from browsers, messaging apps, cryptocurrency wallets, and gaming platforms.
  • The malware avoids detection by disabling Microsoft Defender in its working folder and performs anti-analysis checks before executing.

Cybersecurity researchers revealed an active malware campaign called Stealit that exploits Node.js’ Single Executable Application (SEA) feature for distributing malicious payloads. The campaign uses counterfeit installers for popular games and VPNs uploaded to sites such as Mediafire and Discord. This method allows the malware to run on systems without Node.js installed.

- Advertisement -

Fortinet FortiGuard Labs reported that some versions of Stealit also use the open-source Electron framework. Stealit offers its malware as a subscription service with pricing for Windows stealing tools ranging from $30 for a weekly license to $500 for a lifetime license. The Android remote access trojan (RAT) subscriptions cost between $100 and $2,000.

According to security researchers Eduardo Altares and Joie Salvio, “Both approaches are effective for distributing Node.js-based malware, as they allow execution without requiring a pre-installed Node.js runtime or additional dependencies.” The threat actors behind Stealit advertise their services as professional data extraction solutions, which include file theft, remote control of webcams, live screen monitoring, and Ransomware deployment for Android and Windows.

The malware begins by installing core components after verifying it is not in a Sandbox or virtual environment, using a 12-character Base64-encoded authentication key to connect to its command-and-control server. It then disables Microsoft Defender antivirus protection for the folder containing these files.

Stealit comprises three main executables: save_data.exe, which drops a tool for extracting data from Chromium-based browsers; stats_db.exe, aimed at stealing information from messaging apps, cryptocurrency wallets, and gaming apps; and game_cache.exe, which establishes persistence on the infected device and allows real-time screen streaming, command execution, and file transfers.

- Advertisement -

Fortinet highlighted that Stealit leverages the experimental Node.js SEA feature, still under development, to deliver malicious scripts more easily to machines without requiring Node.js. “Threat actors behind this may be exploiting the feature’s novelty, relying on the element of surprise, and hoping to catch security applications and malware analysts off guard.”

For more details, the Node.js Single Executable Applications feature and the Fortinet report provide further insights.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Morgan Stanley Warns Limited Cybercabs May Hurt Tesla Shares

Morgan Stanley reiterated an 'Equal Weight' rating and $400 price target on Tesla, implying...

NYDFS tells X Money to halt interest payments to New Yorkers

NYDFS told X Money it cannot pay bank-like interest on non-bank deposits for New...

Remixpoint sells $5.5M altcoins, nets $736K gain to focus on Bitcoin

Remixpoint sold its entire holdings of ETH, SOL, XRP, and DOGE for approximately $5.5...

Two GeoNetwork Flaws Enable Unauthenticated Remote Code Execution

Two critical vulnerabilities in GeoNetwork can be chained for unauthenticated remote code execution (RCE),...

SEC proposes first blockchain-era transfer agent rule update

The SEC proposed the first major update to transfer agent rules since the 1980s,...

Must Read

14 Ways On How to Make Money with Cryptocurrency

Many people want to make money with cryptocurrency because they have heard the success stories of people who became millionaires from zero.If you...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading