INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Node.js Malware Delivery Tool Emerges in Targeted Attacks Recently
| 2026-09-03 12:57 CRITICAL MEDIUM MALWARE & BOTNETS
Executive Summary
AI-generated
A recent surge in [IOC HIDDEN • LOGIN REQUIRED] abuse has been observed since February 2026, with multiple attacks targeting government departments, technology companies, and hotels across the United States. The attackers used various tactics, including Cobalt Strike and JavaScript-based malware, to gain access to systems. Notably, some of these attacks were linked to ransomware operations, highlighting a growing threat landscape. In one instance, attackers installed [IOC HIDDEN • LOGIN REQUIRED] from its official site to run an implant commanded via the Ethereum blockchain. This resurgence in [IOC HIDDEN • LOGIN REQUIRED] abuse has been observed since March 2026 and may be attributed to the old but still effective technique making a comeback.
Technical Mitigations AI-generated
• Implement signature-based detection for <a href="/auth/login?next=/detail/-GbzaqAB-1kL6CVYP6iu" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> binaries to evade malicious payloads.
• Utilize behavioral analysis and anomaly detection techniques to identify suspicious activity related to ClickFix initial access methods.
• Leverage sandboxing solutions to analyze and block malicious JavaScript code executed by attackers using the legitimate, signed <a href="/auth/login?next=/detail/-GbzaqAB-1kL6CVYP6iu" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> binary.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hu•••••.top
mu•••••.com
ww•••••.com
cs•••••.com
no•••••.exe
no•••••.js
No•••••.js
hxxp://••••••••••••••••••••
3f797a••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
fb3630••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
59e3c4••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
d27054••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Cobalt StrikeCobalt StrikeBlack BastaBlack BastaEmbargoEmbargoQilinQilin
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
cryptocurrencycryptocurrency
financefinance
governmentgovernment
hospitalityhospitality
retailretail
technologytechnology
Incident Timeline
February 2026
Threat actors associated with initial access broker Woodgnat have exploited vulnerabilities in Node.js to target various organizations since February 2026.
Click on any entity below to view its context and source!
industry
Technology
A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels.
industry
Government
A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels.
observable
Node.js
A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels.
tactic
Ransomware
The trusted JavaScript runtime has featured in multiple attacks since February 2026, some linked to ransomware.
tactic
T1059.007 - JavaScript
The trusted JavaScript runtime has featured in multiple attacks since February 2026, some linked to ransomware.
organisation
Ethereum
In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques.
organisation
EtherHiding
In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques.
organisation
ModeloRAT
Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.
organisation
ClickFix
Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.
2026/09/03
Threat actors are exploiting Node.js in attacks, using the trusted JavaScript runtime to deploy malicious payloads and chain PowerShell and Windows command-line tools.
Click on any entity below to view its context and source!
organisation
IOC - Node.js
IOC - Node.js: Old Technique Makes a Comeback.
organisation
Ethereum
In one case, attackers installed it from its official site to run an implant commanded via the Ethereum blockchain.
victims
31 organizations
"
The disclosure comes as GuidePoint Security said attackers have compromised at least 31 organizations, including e-commerce, professional services, and retail logistics businesses, through a ClickFix campaign that serves fake CAPTCHA verificati…
infrastructure
Windows
…Woodgnat attack chains are characterized by the abuse of "node.exe" to execute attacker JavaScript and chain PowerShell and Windows command-line tools, as well as a malicious Chrome extension named
NexShield
as part of a ClickFix variant dubbed C…
…actions under the pretext of fixing an error or proving they are not bots by copying a command presented in the lure and pasting it onto the Windows Run dialog or the Windows Terminal app, effectively compromising their own systems in the process.
Tactical Metrics
Metrics
victims
31
Organizations
Click for context!
"
The disclosure comes as GuidePoint Security said attackers have compromised at least 31 organizations, including e-commerce, professional services, and retail logistics businesses, through a ClickFix campaign that serves fake CAPTCHA verificati…
Metrics
infrastructure
Windows
Affected Product
…Woodgnat attack chains are characterized by the abuse of "node.exe" to execute attacker JavaScript and chain PowerShell and Windows command-line tools, as well as a malicious Chrome extension named
NexShield
as part of a ClickFix variant dubbed C…
…actions under the pretext of fixing an error or proving they are not bots by copying a command presented in the lure and pasting it onto the Windows Run dialog or the Windows Terminal app, effectively compromising their own systems in the process.
Intelligence Sources
The Hacker News
2026-09-03
AlienVault OTX
2026-09-04
IOC - Node.js: Old Technique Makes a Comeback
AlienVault OTX
AlienVault OTX
2026-09-03
Node.js: Old Technique Makes a Comeback
AlienVault OTX
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:43
Comprehensive Tactical Telemetry
Highly Correlated Entities
19x
organisation
Identified Entity
Ethereum
entity
8x
industry
Targeted Sector
Technology
sector
7x
timeline
Temporal Reference
February 2026
date
4x
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
3x
tactic
Cyber Operation Type
Ransomware
tactic
3x
malware
Malware Payload
Qilin
tool
Contextual Telemetry
Context Block
4 METRICS
target region
Target Country
United States
country
malware
Offensive Tool
Cobalt Strike
tool
victims
Organizations
31
organizations
infrastructure
Affected Product
Windows
software
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.