JustAskJacky is a family of malicious Node.js applications that masquerade as helpful AI assistants or utility tools while covertly performing malicious activity on victim systems. It functions as a trojanized application: the lure software often provides the expected user-facing functionality, but also conducts background reconnaissance and executes arbitrary commands directly in memory. Observed variants have also delivered and run cryptomining code in memory, indicating post-compromise monetization beyond simple access.
The malware is typically distributed as seemingly legitimate installers promoted online as useful AI or utility software. This deceptive presentation relies on social engineering rather than exploit-driven delivery, making the malware notable for blending plausible functionality with hidden malicious behavior. Red Canary has tracked this family under multiple lure-themed names, indicating a broader campaign pattern built around repackaged Node.js applications.
On infected Windows systems, JustAskJacky has been observed establishing persistence through scheduled tasks. It communicates with remote command-and-control infrastructure using domain-generation-like patterns and supports in-memory command execution, which can reduce forensic visibility and complicate detection. Its core behaviors support reconnaissance, persistence, post-exploitation, and defense evasion. The family has been observed in prevalence reporting during both 2025 and 2026, indicating sustained operational use rather than a one-off campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A family of malicious NodeJS applications disguised as AI or utility tools that performs reconnaissance and executes arbitrary commands in memory.
JustAskJacky is a family of malicious NodeJS applications that disguise themselves as AI or utility tools, performing reconnaissance and executing arbitrary commands in memory.
Family of malicious NodeJS applications that masquerade as helpful AI or utility tools while conducting reconnaissance and executing arbitrary commands in memory in the background. It establishes persistence via scheduled tasks and can receive and execute arbitrary JavaScript from its C2, including cryptomining payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.