Hackers Exploit Trusted Node.js Tool to Sneak Malware Past Defences
Security researchers at Symantec have identified a growing trend of attackers misusing Node.js, a widely trusted JavaScript runtime used by developers worldwide, to distribute malware. Since February 2026, this technique has been observed in targeted attacks against government departments, technology companies, and hotels.
The appeal of this method for attackers lies in the fact that node.exe, the executable used to run Node.js applications, is a legitimate and commonly whitelisted piece of software on many business networks. By disguising malicious activity as ordinary Node.js processes, attackers can bypass security tools that might otherwise flag suspicious or unfamiliar executables, making detection significantly harder for defenders relying on traditional allow-list based security controls.
This approach reflects a broader trend of attackers 'living off the land' — using trusted, legitimate software already present in an environment rather than introducing obviously malicious tools that are more likely to trigger alerts. For small and medium businesses that use developer tools or web applications built on Node.js, this means traditional antivirus checks based solely on file reputation may not be enough to catch this kind of threat.