← All articles

Attackers abuse the trusted Node.js runtime to run malware past defenses

Symantec reported that threat actors are abusing the legitimate, digitally signed Node.js runtime to run malicious JavaScript while slipping past security tools, in attacks on government, technology, and hospitality targets since February. Because the Node.js executable is a trusted developer tool, defenses rarely flag it, so instead of dropping a malicious program the attackers stage the genuine runtime and keep their harmful logic in interpreted scripts. They gain persistence through a Windows registry startup key and, in one case, pulled command-and-control instructions from the blockchain using a technique called EtherHiding. The activity has been tied to a ClickFix social-engineering entry point and an initial-access broker.

Check
Hunt for unexpected Node.js installations on machines that should not run developer tools, suspicious registry startup entries invoking the runtime, and outbound traffic to blockchain endpoints used for command and control.
Affected
Windows environments where a signed Node.js runtime can be introduced and run scripts unnoticed; attackers use it to execute malicious JavaScript, persist through registry keys, and evade tools that trust the binary.
Fix
Apply application control to restrict where the Node.js runtime may run, alert on its use outside development, monitor script execution and registry run-key changes, and block known blockchain command-and-control and ClickFix infrastructure.