CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Node.js Backdoor Used in DPRK Malvertising Campaign

July 30, 2026

A Node.js backdoor deployed via fake macOS updates, using LaunchAgent for persistence and Ethereum smart contracts for C2 communication. It polls the server every five minutes to execute JavaScript payloads.