A new Stealit malware campaign has been identified by Fortinet’s FortiGuard Labs, targeting Microsoft Windows users through the abuse of Node.js’ Single Executable Application (SEA) feature. The campaign marks a shift from previous Stealit operations, which relied on the Electron framework to package and distribute malicious payloads. By utilizing the SEA feature, attackers can bundle all necessary scripts and assets into a single executable, allowing the malware to run on systems without a pre-installed Node.js runtime or additional dependencies. This approach increases the likelihood of successful infections, as it reduces the technical barriers for execution on victim machines. The malware is primarily distributed via fake installers for popular games and VPN applications, which are uploaded to widely used file-sharing platforms such as Mediafire and Discord. These installers are often disguised using PyInstaller and compressed archives to further evade detection. Once executed, the malware performs several anti-analysis checks, including detecting debuggers, virtual environments, and suspicious processes, terminating itself if such conditions are found. A notable technical detail is the writing of a Base64-encoded, 12-character authentication key to the %temp%\cache.json file, which is used for communication with the command-and-control (C2) server. The Stealit operation is run as a malware-as-a-service (MaaS), offering various subscription plans for its data extraction tools, including a remote access trojan (RAT) with capabilities such as file extraction, webcam control, live screen monitoring, and ransomware deployment. The service targets both Windows and Android platforms, with pricing tiers ranging from weekly to lifetime licenses. The operators have demonstrated operational security by frequently relocating their C2 infrastructure, moving from domains like stealituptaded.lol to iloveanimals.shop. The campaign’s impact is significant, as compromised machines fall under the control of the threat actors, who can exfiltrate sensitive information for use in further attacks. The campaign’s use of advanced obfuscation and anti-analysis techniques makes detection and mitigation more challenging for defenders. Organizations are advised to be vigilant against suspicious installers, especially those distributed via unofficial channels, and to monitor for indicators of compromise associated with Stealit. The campaign underscores the evolving tactics of cybercriminals in leveraging new software features and distribution methods to maximize reach and evade security controls. Security teams should update their detection mechanisms to account for Node.js SEA-based malware and educate users about the risks of downloading software from untrusted sources. The ongoing nature of the campaign and its professionalized service model highlight the persistent threat posed by MaaS operations in the current cyber threat landscape.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that newer Stealit variants had moved back to Electron-based packaging while encrypting embedded Node.js scripts with AES-256-GCM. Despite the packaging change, the newer samples retained behavior similar to the SEA-based variants.
Analysis showed the installer stored components in randomized AppData paths and attempted to add Microsoft Defender exclusions for those directories. Stealit was found to steal credentials and cryptocurrency wallet data, provide RAT-like features such as screen and webcam access and command execution, and potentially deploy ransomware.
The malware's command-and-control infrastructure moved from stealituptaded[.]lol to iloveanimals[.]shop, a site posing as a commercial service offering Stealit subscriptions and licenses. Campaign infrastructure also served Brotli-compressed components from root.iloveanimals[.]shop.
Fortinet said it began investigating the campaign after observing increased detections of a Visual Basic script that was later identified as a persistence component of Stealit infections. This investigation led to broader analysis of the malware's delivery and execution chain.
Researchers reported that the campaign used Node.js Single Executable Application functionality, and in some cases Electron, to bundle malicious JavaScript into standalone executables that run without Node.js installed. The malware used obfuscation and anti-analysis techniques to hinder detection.
A Stealit malware-as-a-service campaign distributed infostealer payloads through trojanized game cheats, cracked software, and VPN installers shared via platforms such as MediaFire and Discord. The lures delivered standalone malware binaries to Windows users.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityaffairs.com
Open sourcefeeds.fortinet.com
Open sourcehackread.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.