Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical VMware Workstation and Fusion Flaws Let Attackers Execute Code
September 3, 2026
Critical Node.js Vulnerability CVE-2024-2798 Lets Attackers Deploy Malware
September 3, 2026
StreamRAT Android Trojan Grants Full Remote Control via VNC, Accessibility
September 3, 2026
Home/CyberSecurity News/Critical Node.js Vulnerability CVE-2024-2798 Lets Attackers Deploy Malware
CyberSecurity News

Critical Node.js Vulnerability CVE-2024-2798 Lets Attackers Deploy Malware

Key Takeaways Threat actors are increasingly exploiting Node.js, a legitimate JavaScript runtime, to bypass security defenses and deploy various forms of malware. The technique leverages the trusted...

David kimber
David kimber
September 3, 2026 3 Min Read
2 0

Key Takeaways

  • Threat actors are increasingly exploiting Node.js, a legitimate JavaScript runtime, to bypass security defenses and deploy various forms of malware.
  • The technique leverages the trusted nature of Node.js to execute malicious JavaScript, making detection difficult for traditional security tools.
  • Victims include government entities, technology companies, and hotels across Asia and the United States.
  • Observed campaigns involve sophisticated methods like EtherHiding for command and control and the deployment of backdoors such as AdaptixC2, Cobalt Strike, C2Looper, and ModeloRAT.
  • Organizations should monitor for unusual Node.js installations, suspicious registry entries, and unexpected outbound blockchain traffic.

Attackers Leverage Node.js to Evade Detection and Deploy Malware

Cybersecurity researchers at Symantec’s Threat Hunter Team have uncovered a growing trend among malicious actors: the co-option of Node.js, the popular JavaScript runtime environment, to circumvent established security protocols and inject harmful code into target systems. This method allows attackers to operate under the guise of legitimate software, making their activities difficult to detect.

Table Of Content

  • Key Takeaways
  • Attackers Leverage Node.js to Evade Detection and Deploy Malware
  • Node.js Transformed into a Malware Launcher
  • What You Should Do

Since February 2024, multiple distinct threat groups have been observed misusing the digitally signed Node.js executable. This exploitation facilitates the execution of various malware payloads while effectively evading detection by conventional security solutions. The scope of victims is broad, encompassing government departments, technology firms, and hospitality businesses across both Asia and the United States.

The primary appeal of Node.js for attackers stems from its inherent legitimacy. As a signed, trusted developer tool, the node.exe process is rarely flagged as suspicious by security software, providing a stealthy channel for malicious operations.

Node.js Transformed into a Malware Launcher

Rather than directly dropping a traditional malicious executable, threat actors are deploying the authentic Node.js runtime itself. They then utilize it to execute malicious JavaScript, thereby concealing the harmful logic within interpreted scripts instead of a standalone binary. To ensure persistence across system reboots, attackers register the tool silently within a Windows registry Run key, guaranteeing its automatic relaunch each time a victim logs into their machine.

A notable incident involved an Asian technology company where attackers, after encountering repeated blocks in their attempts to deploy AdaptixC2 agents and Cobalt Strike Beacon, resorted to downloading the official Node.js installer directly from nodejs.org. They subsequently employed the runtime to execute an implant that communicated with Ethereum blockchain gateways. This technique, known as EtherHiding, involves embedding commands or payloads within smart contracts on the blockchain.

The same threat group also successfully infiltrated a U.S. fintech firm. In this instance, they deployed C2Looper, a Rust-based backdoor previously documented by Zscaler as malware likely used to establish initial footholds for ransomware operators prior to lateral movement within a network. Shared command-and-control infrastructure, including the domain “datalayerservice,” links these two distinct intrusions to a single, identifiable actor.

Other attack campaigns have combined Node.js abuse with ModeloRAT, a tool believed to be developed by an initial access broker known as Woodgnat or KongTuke. This particular broker has been implicated in facilitating attacks for numerous ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.

Symantec notes the technique is not exclusive to a single group. Since February, a diverse array of actors, varying in skill level and objectives—from laying groundwork for ransomware attacks to engaging in credential and cryptocurrency theft—have adopted the tactic of abusing Node.js.

Among the notable tools observed in conjunction with this method are a new Node.js variant of AsukaStealer, which has been used against hotels in Asia, and EtherRAT, another remote access trojan that relies on blockchain infrastructure for its operations.

What You Should Do

  • Monitor Node.js Installations: Implement strict monitoring for any unexpected or unauthorized installations of Node.js on endpoints, especially on systems not typically used for development.
  • Inspect Registry Run Keys: Regularly audit Windows registry Run keys for unusual or suspicious entries related to Node.js or any other developer tools.
  • Analyze Outbound Network Traffic: Pay close attention to outbound network traffic for connections to blockchain RPC endpoints, such as Ethereum gateways, from machines that should not ordinarily be communicating with such services.
  • Implement Application Whitelisting: Consider implementing application whitelisting to restrict the execution of unauthorized executables and scripts, including those that might leverage legitimate tools like Node.js maliciously.
  • Educate Users: Reinforce security awareness training to help users identify and report suspicious activities, phishing attempts, or unexpected software downloads.
  • Maintain Up-to-Date Security Solutions: Ensure endpoint detection and response (EDR) and other security solutions are updated and configured to detect behavioral anomalies, rather than solely relying on signature-based detection.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEMalwareransomwareSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

StreamRAT Android Trojan Grants Full Remote Control via VNC, Accessibility

Next Post

Critical VMware Workstation and Fusion Flaws Let Attackers Execute Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Sangoma Switchvox RCE Vulnerability Actively Exploited
September 3, 2026
Critical WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection
September 3, 2026
Critical Apache HTTP Server Vulnerability Lets Attackers Phish Users
September 3, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us