Multiple threat actors have revived abuse of the legitimate, signed Node.js runtime to execute malicious JavaScript implants, establish persistence, and bypass signature-based controls. Intrusions at an Asian technology company and a U.S. fintech organization reportedly began with ClickFix lures and PowerShell downloaders, followed by AdaptixC2, Cobalt Strike, and, in the U.S. case, the Rust-based C2Looper backdoor. After payloads were blocked at the Asian victim, operators installed Node.js from nodejs.org, created a Registry Run-key persistence mechanism, and queried Ethereum RPC gateways for command-and-control instructions—activity consistent with EtherHiding. Related campaigns have targeted government entities, hotels, and technology organizations using malware including ModeloRAT, Backdoor.Mistic, EtherRAT, and a Node.js variant of AsukaStealer.
A separate EtherHiding-enabled ClickFix campaign allegedly compromised at least 31 legitimate business websites and used fake CAPTCHA prompts to convince visitors to run malicious commands. Its persistent backdoor retrieved mutable C2 configuration from Polygon smart contracts, making conventional IP- and domain-based blocking less durable; reported capabilities also included Registry and scheduled-task persistence, host fingerprinting, and browser-extension or web-inject activity that could expose banking and cryptocurrency credentials. Organizations should prioritize detection of unauthorized Node.js installations and suspicious JavaScript execution, restrict browser extensions, audit web properties for injected ClickFix content, and monitor blockchain RPC access and behavior-based indicators rather than relying solely on static infrastructure blocks.

Get the actors, campaigns, and ATT&CK mapping behind it.
18 events from the most recent confirmed update back to the earliest known activity.
The U.S. fintech victim received the Rust-based LooperC2, also known as C2Looper, backdoor. Its command-and-control indicator matched previously documented C2Looper infrastructure associated with ransomware-related foothold activity.
The U.S. fintech intrusion deployed a Cobalt Strike Beacon named thread_indirect.exe. The observed AdaptixC2 and Cobalt Strike infrastructure used Devmine-themed and datalayerservice[.]com domains.
Attackers deployed an AdaptixC2 agent at the U.S. fintech victim as part of the intrusion that used ClickFix-style initial access and persistent PowerShell downloaders.
The Asian victim's Node.js implant contacted eth.llamarpc[.]com and mainnet.gateway.tenderly[.]co. Researchers assessed the connections as likely EtherHiding activity to retrieve command-and-control configuration or additional payloads from a smart contract.
The Asian technology victim executed the signed Node.js runtime with a native addon, evasion.node, from the Windows Apps cache. The implant was persisted through a randomly named HKCU Run value that launched node.exe headlessly.
A U.S. fintech organization was compromised after PowerShell connected to summonhood[.]com and used earthquakeist.ps1 as a persistent downloader. Beaconing later shifted to rebronzeal[.]com and continued at near-daily intervals for about 11 weeks.
A Node.js version of AsukaStealer targeted several Asian hotels. The malware can steal credentials, session data, cookies, cryptocurrency-wallet data, and screenshots, and can download additional payloads.
The Asian technology victim downloaded the official Node.js installer from nodejs.org despite the host having no prior routine Node.js use.
An obfuscated PowerShell command launched by explorer.exe at an Asian technology company downloaded and executed a script from strapness[.]com. The accumulatally.ps1 downloader subsequently persisted for months and was repeatedly launched as a Windows service.
Multiple threat actors began a resurgence of abuse of the legitimate signed Node.js runtime to execute malicious JavaScript implants, with some activity linked to ransomware.
Iran-linked groups adopted EtherHiding by early 2026, expanding use of blockchain-based command-and-control redirection.
North Korean state-linked actors had adopted EtherHiding by late 2025, according to the reported campaign analysis.
North Korean-linked UNC5342 launched an EtherHiding campaign that used a smart contract to deliver Jadesnow, including an InvisibleFerret variant with cryptocurrency-stealing objectives.
Criminal groups were first observed using EtherHiding, a technique that uses blockchain smart contracts to dynamically redirect command-and-control infrastructure.
Other attacks combined abuse of the legitimate Node.js runtime with ModeloRAT, while EtherRAT, a blockchain-reliant remote-access trojan, was also observed alongside Node.js abuse. ModeloRAT is believed to be associated with the Woodgnat/KongTuke initial-access broker.
An EtherHiding campaign compromised more than 5,400 small-business websites across over 2,200 organizations, using BNB Smart Chain testnet smart contracts to serve browser payloads. Alongside ClickFix fake-CAPTCHA delivery, a newer variant used a forged WebRTC session answer to establish an encrypted UDP C2 data channel and execute streamed code in the browser.
A reported campaign compromised at least 31 legitimate e-commerce, professional-services, and retail-logistics websites, presenting search-engine visitors with fake CAPTCHA prompts that induced ClickFix command execution. The resulting persistent backdoor retrieved updated command-and-control details from Polygon smart contracts, while some cleaned websites were silently compromised again weeks later.
During the intrusion of an Asian technology company, attackers' attempts to deploy AdaptixC2 and Cobalt Strike beacons were blocked. They subsequently shifted to downloading the official Node.js installer and using node.exe to run a malicious implant for long-term access.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 170 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
8 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourcenetskope.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcemalware.news
Open sourcesecurity.com
Open sourceguidepointsecurity.com
Open sourcestormshield.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.