Potentially Suspicious Inline JavaScript Execution via NodeJS Binary

 Original Source: [Sigma source]
Title: Potentially Suspicious Inline JavaScript Execution via NodeJS Binary
Status: experimental
Description:Detects potentially suspicious inline JavaScript execution using Node.js with specific keywords in the command line.
References:
  -https://www.microsoft.com/en-us/security/blog/2025/04/15/threat-actors-misuse-node-js-to-deliver-malware-and-other-malicious-payloads/
Author: Microsoft (idea), Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-04-21
modified:None
Tags:
  • -'attack.execution'
  • -'attack.t1059.007'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\node.exe' OriginalFileName:'node.exe' Product:'Node.js'   selection_cmd:
    CommandLine|contains|all:
      -'http'
      -'execSync'
      -'spawn'
      -'fs'
      -'path'
      -'zlib'

  condition:all of selection_*
Falsepositives:
  -Legitimate scripts using Node.js with these modules
Level: medium