Attackers are exploiting the legitimacy of Node.js runtime to deliver malware in targeted campaigns, using the trusted tool as a cover for malicious payloads that bypass traditional security defenses. You should implement strict controls over Node.js exec
Read the full article: https://thehackernews.com/2026/09/attackers-turn-trusted-nodejs-runtime.html