{"id":243607,"date":"2026-09-04T01:35:07","date_gmt":"2026-09-04T06:35:07","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/09\/attackers-turn-trusted-node-js-runtime-into-malware-delivery-tool-in-targeted-attacks"},"modified":"2026-09-04T01:35:07","modified_gmt":"2026-09-04T06:35:07","slug":"attackers-turn-trusted-node-js-runtime-into-malware-delivery-tool-in-targeted-attacks","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/09\/attackers-turn-trusted-node-js-runtime-into-malware-delivery-tool-in-targeted-attacks","title":{"rendered":"Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/attackers-turn-trusted-node-js-runtime-into-malware-delivery-tool-in-targeted-attacks2.jpg\"><\/a><\/p>\n<p>Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.<\/p>\n<p>According to a <a href=\"https:\/\/www.security.com\/threat-intelligence\/node-js-returns-ransomware\" target=\"_blank\">new report<\/a> published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.<\/p>\n<p>\u201cThe technique\u2019s appeal is that node.exe (the binary that runs Node.js) is a legitimate, signed developer tool,\u201d the Broadcom-owned cybersecurity division said in a report shared with The Hacker News. \u201cThe attacker\u2019s malicious code lives in interpreted scripts rather than in a binary, making it less likely to trigger signature-based detection, while a registry Run key entry can relaunch the payload at every login.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. \u201cThe technique\u2019s [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,1490],"tags":[],"class_list":["post-243607","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode","category-government"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/243607","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=243607"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/243607\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=243607"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=243607"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=243607"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}