Microsoft warns of a malvertising campaign using Node.js to deliver info-stealing malware via fake crypto trading sites like Binance and TradingView.
Threat actors are increasingly using Node.js to deploy malware, bypass security tools, and persist in systems.
In these attacks, malvertising is used to lure users to fake sites, and once executed, a malicious DLL collects system data and delivers further payloads.
Microsoft has provided recommendations to mitigate threats related to the misuse of Node.js.