NodeLoader: A New Malware Family Exploits Node.js for Stealthy Attacks
ID: adcded31-2406-586c-a04e-7154dd10398e
STIX ID: report--adcded31-2406-586c-a04e-7154dd10398e
Feed Name: securityonline.info
Threat Score
**NodeLoader** is a Node.js-based Windows malware campaign that packages JavaScript applications into large standalone executables (via npm pkg) to evade detection, distributes via fake gaming sites and malicious YouTube links, escalates privileges using the sudo-prompt module to bypass UAC, and deploys second-stage payloads including XMRig (cryptominer), Phemedrone and Lumma stealers (credential/browser data exfiltration) using PowerShell scripts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
