TaskWeaver

TaskWeaver is a modular, heavily obfuscated Node.js malware loader identified by the Blackpoint Adversary Pursuit Group. Explore its key TTPs, associated tooling, indicators of compromise, and recommendations for defending Windows environments.

Download the Threat Snapshot

About This Threat Profile

First Observed: June 21, 2026

Threat Type: Loader

Platform: Windows

Confidence: High

Aliases and Related Activity:

  • Associated with Djinn Stealer
  • Observed following exploitation of SimpleHelp vulnerability CVE-2026-48558

Description of TaskWeaver

TaskWeaver is a modular, heavily obfuscated Node.js malware loader identified by the Blackpoint Adversary Pursuit Group (APG). It is designed to fingerprint compromised systems, establish encrypted command and control (C2) communications, and retrieve and execute additional payloads.

Rather than embedding a fixed set of post-exploitation capabilities, TaskWeaver functions as a reusable delivery framework capable of deploying follow-on malware such as information stealers while leveraging the trusted Node.js runtime to blend in with legitimate developer activity.

Blackpoint researchers have observed TaskWeaver in activity associated with Djinn Stealer and following exploitation of the SimpleHelp vulnerability CVE-2026-48558. Its modular design and use of a legitimate JavaScript runtime provide operators with a flexible mechanism for executing additional malicious payloads within compromised Windows environments.

Key TTPs

TaskWeaver activity incorporates several techniques mapped to the MITRE ATT&CK framework, including JavaScript execution, obfuscation, masquerading, system information discovery, and command-and-control traffic over web protocols.

Tactic Technique ATT&CK ID
Execution Command and Scripting Interpreter: JavaScript T1059.007
Stealth Obfuscated Files or Information T1027
Stealth Masquerading T1036
Discovery System Information Discovery T1082
Command and Control Application Layer Protocol: Web Protocols T1071.001

Tooling & Family Links

Blackpoint APG observed TaskWeaver working alongside additional tooling and legitimate software abused during the intrusion chain.

Tool / Family Role
Djinn Stealer Observed second-stage information stealer delivered by TaskWeaver.
Node.js (node.exe) Legitimate JavaScript runtime abused to execute TaskWeaver.

Indicators of Compromise

Organizations investigating potential TaskWeaver activity should review the following execution patterns, file indicators, network infrastructure, and URI behavior identified by Blackpoint APG.

Type Value
TaskWeaver Execution node.exe <path>\jquery.js
TaskWeaver 00cc86d1144020c24c8fbb3a8dc6b908926497ebd23be3bf854360f93d1c8f4c
TaskWeaver jquery.js
TaskWeaver C2 a[.]dev-tunnels[.]com
TaskWeaver URI Pattern POST /api/<base64url>.<base64url>.<base64url>

Recommendations

  • Apply application control and restrict or monitor the execution of Node.js (node.exe) on systems where it is not operationally required.
  • Monitor for abnormal outbound HTTPS communications initiated by node.exe, particularly to newly observed or low-reputation domains.
  • Limit remote management software access using least-privilege principles and multi-factor authentication (MFA), and regularly audit technician accounts for unauthorized activity.
  • Place administrative interfaces behind a VPN or identity-aware proxy and enforce phishing-resistant MFA, source restrictions, and dedicated administrative workstations.
  • Restrict temporary tunneling services, such as trycloudflare[.]com, when not required.

Download the TaskWeaver Threat Snapshot

Get the complete Blackpoint Cyber SOC Threat Snapshot for a concise technical reference covering TaskWeaver’s observed behavior, ATT&CK mappings, indicators of compromise, and defensive recommendations.

Download the Threat Snapshot

Additional TaskWeaver Research

For a deeper analysis of the intrusion chain and malware behavior, read Blackpoint Cyber’s A Djinn in the Machine: TaskWeaver’s Node.js Intrusion Chain.

DATE PUBLISHEDSeptember 4, 2026
AUTHORBlackpoint Cyber

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY