The abuse of Node.js has resurfaced, with multiple threat actors targeting government departments, technology companies, and hotels since February 2026. Attackers use the legitimate, signed node.exe runtime to execute malicious scripts, evade signature-based detection, and maintain persistence through registry Run keys....