INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Node.js Malware Delivery Tool Emerges in Targeted Attacks Recently

| 2026-09-03 12:57 CRITICAL MEDIUM MALWARE & BOTNETS
Executive Summary
AI-generated
A recent surge in [IOC HIDDEN • LOGIN REQUIRED] abuse has been observed since February 2026, with multiple attacks targeting government departments, technology companies, and hotels across the United States. The attackers used various tactics, including Cobalt Strike and JavaScript-based malware, to gain access to systems. Notably, some of these attacks were linked to ransomware operations, highlighting a growing threat landscape. In one instance, attackers installed [IOC HIDDEN • LOGIN REQUIRED] from its official site to run an implant commanded via the Ethereum blockchain. This resurgence in [IOC HIDDEN • LOGIN REQUIRED] abuse has been observed since March 2026 and may be attributed to the old but still effective technique making a comeback.
Technical Mitigations AI-generated
• Implement signature-based detection for <a href="/auth/login?next=/detail/-GbzaqAB-1kL6CVYP6iu" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> binaries to evade malicious payloads. • Utilize behavioral analysis and anomaly detection techniques to identify suspicious activity related to ClickFix initial access methods. • Leverage sandboxing solutions to analyze and block malicious JavaScript code executed by attackers using the legitimate, signed <a href="/auth/login?next=/detail/-GbzaqAB-1kL6CVYP6iu" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> binary.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hu•••••.top
mu•••••.com
ww•••••.com
cs•••••.com
no•••••.exe
no•••••.js
No•••••.js
hxxp://••••••••••••••••••••
3f797a••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
fb3630••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
59e3c4••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
d27054••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Cobalt StrikeCobalt StrikeBlack BastaBlack BastaEmbargoEmbargoQilinQilin
Target & Sectors
NORTH_AMERICA NORTH_AMERICA cryptocurrencycryptocurrency financefinance governmentgovernment hospitalityhospitality retailretail technologytechnology
Incident Timeline
‎February 2026
Threat actors associated with initial access broker Woodgnat have exploited vulnerabilities in Node.js to target various organizations since February 2026.
industry Technology
industry Government
observable Node.js
tactic Ransomware
tactic T1059.007 - JavaScript
organisation Ethereum
organisation EtherHiding
organisation ModeloRAT
organisation ClickFix
‎2026/09/03
Threat actors are exploiting Node.js in attacks, using the trusted JavaScript runtime to deploy malicious payloads and chain PowerShell and Windows command-line tools.
organisation IOC - Node.js
organisation Ethereum
victims 31 organizations
infrastructure Windows
Tactical Metrics
Metrics
victims
31
Organizations
Metrics
infrastructure
‎Windows
Affected Product
Intelligence Sources
AlienVault OTX 2026-09-04
AlienVault OTX 2026-09-03