Attackers Leverage Node.js as Malware Distribution Vector in Targeted Campaigns
Threat actors are exploiting the trusted Node.js runtime environment to distribute malware in targeted attacks against government agencies, technology…
Audit installations of Node.js in corporate infrastructure to identify unnecessary deployments; enforce controls restricting node.exe execution in production environments; monitor for anomalous runtime behavior including unauthorized network connections and child process spawning. Monitor Symantec threat intelligence for additional indicators of compromise.