ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

Node.js used to deliver malware in targeted attacks

Symantec said attackers had used Node.js in attacks since February 2026 against government departments, technology companies and hotels, while GuidePoint Security described a separate ClickFix campaign affecting at least 31 organisations.

The Hacker News

Symantec Threat Hunter Team said multiple attackers had used Node.js in cyber intrusions since February 2026, targeting government departments, technology companies and hotels. It said node.exe was attractive because it was a legitimate signed tool and because script-based payloads were less likely to trigger signature checks.

In one intrusion against an unnamed Asian technology company, which Symantec said ran from 23 March to 25 July 2026, the attackers downloaded the official Node.js installer from nodejs.org. Symantec said they then used the runtime to install a malicious implant for long-term access and command retrieval through EtherHiding, after ClickFix had given them access.

Symantec said the same approach had also appeared with ModeloRAT and Mistic, which it assessed as the work of KongTuke, also called Woodgnat. The company said earlier Woodgnat chains had used node.exe to run attacker JavaScript and to chain PowerShell and Windows command-line tools, along with the NexShield browser extension and the GateKeeper .NET payload.

Symantec also linked the method to a U.S. fintech organisation. It said Zscaler ThreatLabz had documented C2Looper last month, while the earliest activity in that case dated to 6 May 2026 and had first involved AdaptixC2 and a Cobalt Strike Beacon.

GuidePoint Security said a separate ClickFix campaign had compromised at least 31 organisations, including e-commerce, professional services and retail logistics businesses. Jean-Pierre Mouton said the campaign used the Polygon blockchain as a way to update C2 details, and GuidePoint advised website checks, browser-extension controls and staff training.

Named in this story

People

Jean-Pierre Mouton
was the GuidePoint Security researcher quoted on the campaign

Companies

Broadcom
owns Symantec's cybersecurity division
GuidePoint Security
said a separate ClickFix campaign had compromised at least 31 organisations

Organisations

Symantec Threat Hunter Team
published the report on the attack chains
KongTuke
was the initial access broker Symantec linked to the activity
Zscaler ThreatLabz
had documented C2Looper the previous month

Products and systems

Node.js
was abused as the runtime for payload delivery
ClickFix
was used as the social engineering method for initial access
EtherHiding
was used to locate command-and-control details and retrieve commands
AdaptixC2
was one of the tools attackers tried to deploy
Cobalt Strike
was one of the tools attackers tried to deploy
ModeloRAT
appeared alongside the Node.js abuse in some attacks
Mistic
appeared alongside the Node.js abuse in some attacks
C2Looper
was the Rust-based backdoor deployed in one intrusion
GateKeeper
was a .NET payload used in the attacks
NexShield
was a malicious Chrome extension used in the attacks

How the source tells it

The piece read like a security alert, with a generally urgent register but little overt flourish.

  • urgency recent incidents, active timelines and closing mitigation advice kept the story in alert mode