SECURITY·중요도 8·2026. 09. 03.·The Hacker News

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

── KO ──────────────────

공격자들이 신뢰받는 Node.js 런타임을 악성 코드 전파 도구로 활용하고 있다.

공격자들이 신뢰되는 Node.js JavaScript 런타임을 이용하여 악성 페이로드를 배포하는 사이버 공격을 감행하고 있다. Symantec의 위협 헌터 팀이 발표한 보고서에 따르면, 이 공격 방법은 2026년 2월부터 정부 부서, 기술 회사 및 호텔을 대상으로 사용되고 있다. node.exe의 활용은 공격자들에게 매력적인 기법으로 자리 잡고 있다.


── EN ──────────────────

Attackers are using the trusted Node.js runtime as a tool for malware delivery.

Threat actors are leveraging the trusted Node.js JavaScript runtime to deploy malicious payloads in cyber attacks. According to a report from the Symantec Threat Hunter Team, this attack method has been used against government departments, technology companies, and hotels since February 2026. The use of node.exe has become an appealing technique for these attackers.

원문 보기 →목록으로