logo

New ClickFix Campaign Unveiled: Modular NodeJS Malware Targets Windows Users

ID: c8537fb7-ee83-5aca-99b2-731cb0fce8af

STIX ID: report--c8537fb7-ee83-5aca-99b2-731cb0fce8af

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-10

Date Updated: 2026-04-23

Author: Ddos

...
...

Netskope Threat Labs describes a sophisticated ClickFix campaign that infects Windows users through a fake CAPTCHA which triggers a background PowerShell to download a self-contained MSI (NodeServer-Setup-Full.msi) bundling Node.js; the malware persists via registry, executes modular stealing modules in-memory (never writing core modules to disk), and communicates with a C2 over gRPC tunneled through Tor (using a local SOCKS5 proxy). The report highlights advanced evasion (AV fingerprinting), real-time operator infrastructure revealed by an accidentally leaked admin.proto, and MaaS-like features such as multi-operator role control, wallet tracking for cryptocurrency theft, and Telegram-based notifications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.