logo

Threat actors misuse Node.js to deliver malware and other malicious payloads

ID: 8adf967f-1951-5f4d-907f-abbd9ce92552

STIX ID: report--8adf967f-1951-5f4d-907f-abbd9ce92552

Feed Name: Microsoft Security

Threat Score
70/100

Date Published: 2025-04-15

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence and Microsoft Security Experts

...
...

Since October 2024 Microsoft Defender observed active malvertising campaigns using Node.js to deliver compiled JavaScript payloads and inline scripts that enable persistence, defense evasion, detailed system/browser data collection, and exfiltration to C2 servers; the report details the attack chain (malicious installers with a DLL, scheduled tasks running obfuscated PowerShell to download node.exe and .jsc files), IOCs, MITRE ATT&CK mappings, hunting queries for Defender XDR and Sentinel, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.