TaskWeaver is a previously undocumented, heavily obfuscated Node.js malware loader used in intrusions that exploited the critical SimpleHelp authentication bypass vulnerability CVE-2026-48558. After attackers obtained technician-level access to vulnerable internet-facing SimpleHelp deployments, they abused the platform’s trusted remote-management capabilities to transfer and execute TaskWeaver on managed endpoints. The malware was observed masquerading as a benign JavaScript library and executed through the Node.js runtime on compromised systems.
TaskWeaver functions as a modular payload-delivery framework rather than a fixed post-exploitation implant. It fingerprints infected hosts, establishes encrypted communications with attacker-controlled infrastructure, and retrieves additional JavaScript payloads for execution with full Node.js functionality. Reported analysis indicates it was designed to evade static analysis through heavy obfuscation, runtime reconstruction of module-loading functionality, and encrypted command-and-control exchanges. In observed attacks, its primary role was to deliver Djinn Stealer, though its architecture supports delivery of arbitrary follow-on payloads.
The malware has been associated with an unidentified threat actor exploiting exposed SimpleHelp remote monitoring and management infrastructure, creating particular risk for managed service providers and enterprise IT environments where a compromised RMM server can provide broad downstream access. TaskWeaver has been observed in campaigns targeting developer and administrative workstations as an initial loader in a broader credential- and secret-theft operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Blackpoint Cyber found that an attacker exploited the flaw, tracked as CVE-2026-48558, to obtain a trusted technician session on an internet-facing SimpleHelp server. In affected configurations, SimpleHelp failed to check the cryptographic signature of identity tokens in its OpenID Connect login, letting an unauthenticated attacker forge a token and sign in as a technician. | Despite its name, jquery.js is a modular Node.js loader that its researchers track as TaskWeaver, built to evade static analysis.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
the attacker exploited the flaw, tracked as CVE-2026-48558, to obtain a trusted technician session on an internet-facing SimpleHelp server
SimpleHelp failed to check the cryptographic signature of identity tokens in its OpenID Connect login, letting an unauthenticated attacker forge a token and sign in as a technician.
TaskWeaver was a modular Node.js loader designed to fingerprint the compromised system, establish encrypted communications with attacker-controlled infrastructure, and retrieve and execute additional JavaScript payloads with full access to the Node.js runtime. | TaskWeaver sent the beacon as an HTTPS POST request with a text/plain body.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously unreported malware family deployed after exploitation of the SimpleHelp authentication bypass on compromised RMM deployments.
A previously undiscovered malware sample identified during attacks exploiting the SimpleHelp vulnerability CVE-2026-48558.
A modular Node.js loader disguised as jquery.js and deployed through compromised SimpleHelp RMM functionality. It is designed to evade static analysis and exposes a single command, "deliver," allowing operators to run arbitrary code with full Node.js access and drop follow-on payloads such as stealers, backdoors, or ransomware.
A heavily obfuscated JavaScript/Node.js loader delivered after exploitation of CVE-2026-48558 in SimpleHelp. It downloads and executes under Node.js, beacons to a C2 server using AES-256-GCM with RSA-OAEP key wrapping, reconstructs access to require() at runtime to evade static analysis, collects system information, and retrieves/decrypts follow-on payloads such as Djinn Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.