Threat Intelligence

Hackers Exploit Trusted Node.js Tool to Sneak Malware Past Defences

The Hacker News · 3 Sept 2026
Key Takeaway Businesses using Node.js or other developer tools should monitor for unusual process behaviour rather than relying only on whether software is 'trusted,' and should apply application control and behavioural monitoring where possible.

Security researchers at Symantec have identified a growing trend of attackers misusing Node.js, a widely trusted JavaScript runtime used by developers worldwide, to distribute malware. Since February 2026, this technique has been observed in targeted attacks against government departments, technology companies, and hotels.

The appeal of this method for attackers lies in the fact that node.exe, the executable used to run Node.js applications, is a legitimate and commonly whitelisted piece of software on many business networks. By disguising malicious activity as ordinary Node.js processes, attackers can bypass security tools that might otherwise flag suspicious or unfamiliar executables, making detection significantly harder for defenders relying on traditional allow-list based security controls.

This approach reflects a broader trend of attackers 'living off the land' — using trusted, legitimate software already present in an environment rather than introducing obviously malicious tools that are more likely to trigger alerts. For small and medium businesses that use developer tools or web applications built on Node.js, this means traditional antivirus checks based solely on file reputation may not be enough to catch this kind of threat.

Node.js malware living-off-the-land targeted-attacks threat-detection

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.