# Attackers use signed Node.js runtime to deliver malware

_Thursday, September 3, 2026 at 6:43 AM EDT · Security · Latest · Tier 2 — Notable_

![Attackers use signed Node.js runtime to deliver malware — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixQdi-o7wSstsDvvGluX8EDCUhGUHwpKjSkMSaigZZkFOEI_mWS0kLYvjSaG9olG2Y8GYxqH2kKRUtT82RVMLfW-FuBdrWMbGSfJMVVK3YAL3FClWT6t0Dz33NzHEYK1dL93JLl7YzyETY1i9ZYpRty-BG5Vfk_vGUggKigBtpQZxKuUW8-Jg3m9xZV8BL/s1700-nu-rw-lo-l85-e365/jsnode.jpg)

Threat actors have used the legitimate Node.js runtime to deploy malicious payloads in attacks on government departments, technology companies and hotels since February 2026, according to Symantec's Threat Hunter Team.

In one intrusion targeting an Asian technology company, attackers downloaded the official Node.js installer and used its signed runtime to run an implant and retrieve commands or tools. The technique places malicious code in interpreted scripts and can use a registry Run key to relaunch it at login.

Related activity has also targeted a U.S. fintech organization.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/attackers-turn-trusted-nodejs-runtime.html)

---
Canonical: https://techandbusiness.org/newswire/PXR9Ml4KT7ISO2A8ih_m4G
Retrieved: 2026-09-03T15:59:53.335Z
Publisher: Tech & Business (techandbusiness.org)
