Stealit Malware Abuses Nodejs Single Executable Feature via Game and VPN Installers
Posted on October 10, 2025 • 1 min read • 58 wordsCybersecurity researchers have disclosed details of an active malware campaign called Stealit that has leveraged Node.js Single Executable Application (SEA) feature as a way to distribute its payloads. According to Fortinet FortiGuard Labs, select iterations have also employed the open-source Electron framework to deliver the malware. Its assessed that the malware
Cybersecurity researchers have disclosed details of an active malware campaign called Stealit that has leveraged Node.js’ Single Executable Application (SEA) feature as a way to distribute its payloads. According to Fortinet FortiGuard Labs, select iterations have also employed the open-source Electron framework to deliver the malware. It’s assessed that the malware is being propagated through