Suspicious Inline JavaScript Execution by Node.js (node.exe) on Windows
Flags Windows command lines where node.exe is used with JavaScript execution indicators and module keywords consistent with malicious activity.
FreeUnreviewedSigmamediumv1
suspicious-inline-javascript-execution-by-node-js-node-exe-on-windows-8537c866
title: Suspicious Inline JavaScript Execution by Node.js (node.exe) on Windows
id: 21473f5e-2603-4e46-96de-288f441b1d27
status: experimental
description: This rule flags Windows process executions of node.exe that include inline JavaScript-related activity indicated by a set of command-line keywords. Attackers can use Node.js to execute code and interact with network and local resources in a single command, which may help deliver or run malicious payloads. Detection relies on process creation telemetry, matching the node binary and the presence of specific command-line strings such as http, execSync, spawn, and file/crypto-related modules (fs, path, zlib).
references:
- https://www.microsoft.com/en-us/security/blog/2025/04/15/threat-actors-misuse-node-js-to-deliver-malware-and-other-malicious-payloads/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_inline_node_js_execution.yml
author: Microsoft (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-04-21
tags:
- attack.execution
- attack.t1059.007
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \node.exe
- OriginalFileName: node.exe
- Product: Node.js
selection_cmd:
CommandLine|contains|all:
- http
- execSync
- spawn
- fs
- path
- zlib
condition: all of selection_*
falsepositives:
- Legitimate scripts using Node.js with these modules
level: medium
license: DRL-1.1
related:
- id: 8537c866-072e-460d-bfff-aaf39cbd73d3
type: derived
What it detects
This rule flags Windows process executions of node.exe that include inline JavaScript-related activity indicated by a set of command-line keywords. Attackers can use Node.js to execute code and interact with network and local resources in a single command, which may help deliver or run malicious payloads. Detection relies on process creation telemetry, matching the node binary and the presence of specific command-line strings such as http, execSync, spawn, and file/crypto-related modules (fs, path, zlib).
Known false positives
- Legitimate scripts using Node.js with these modules
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.