First Observed: June 21, 2026
Threat Type: Loader
Platform: Windows
Confidence: High
Aliases and Related Activity:
- Associated with Djinn Stealer
- Observed following exploitation of SimpleHelp vulnerability CVE-2026-48558
TaskWeaver is a modular, heavily obfuscated Node.js malware loader identified by the Blackpoint Adversary Pursuit Group. Explore its key TTPs, associated tooling, indicators of compromise, and recommendations for defending Windows environments.
Download the Threat SnapshotFirst Observed: June 21, 2026
Threat Type: Loader
Platform: Windows
Confidence: High
Aliases and Related Activity:
TaskWeaver is a modular, heavily obfuscated Node.js malware loader identified by the Blackpoint Adversary Pursuit Group (APG). It is designed to fingerprint compromised systems, establish encrypted command and control (C2) communications, and retrieve and execute additional payloads.
Rather than embedding a fixed set of post-exploitation capabilities, TaskWeaver functions as a reusable delivery framework capable of deploying follow-on malware such as information stealers while leveraging the trusted Node.js runtime to blend in with legitimate developer activity.
Blackpoint researchers have observed TaskWeaver in activity associated with Djinn Stealer and following exploitation of the SimpleHelp vulnerability CVE-2026-48558. Its modular design and use of a legitimate JavaScript runtime provide operators with a flexible mechanism for executing additional malicious payloads within compromised Windows environments.
TaskWeaver activity incorporates several techniques mapped to the MITRE ATT&CK framework, including JavaScript execution, obfuscation, masquerading, system information discovery, and command-and-control traffic over web protocols.
| Tactic | Technique | ATT&CK ID |
|---|---|---|
| Execution | Command and Scripting Interpreter: JavaScript | T1059.007 |
| Stealth | Obfuscated Files or Information | T1027 |
| Stealth | Masquerading | T1036 |
| Discovery | System Information Discovery | T1082 |
| Command and Control | Application Layer Protocol: Web Protocols | T1071.001 |
Blackpoint APG observed TaskWeaver working alongside additional tooling and legitimate software abused during the intrusion chain.
| Tool / Family | Role |
|---|---|
| Djinn Stealer | Observed second-stage information stealer delivered by TaskWeaver. |
| Node.js (node.exe) | Legitimate JavaScript runtime abused to execute TaskWeaver. |
Organizations investigating potential TaskWeaver activity should review the following execution patterns, file indicators, network infrastructure, and URI behavior identified by Blackpoint APG.
| Type | Value |
|---|---|
| TaskWeaver Execution | node.exe <path>\jquery.js |
| TaskWeaver | 00cc86d1144020c24c8fbb3a8dc6b908926497ebd23be3bf854360f93d1c8f4c |
| TaskWeaver | jquery.js |
| TaskWeaver C2 | a[.]dev-tunnels[.]com |
| TaskWeaver URI Pattern | POST /api/<base64url>.<base64url>.<base64url> |
Get the complete Blackpoint Cyber SOC Threat Snapshot for a concise technical reference covering TaskWeaver’s observed behavior, ATT&CK mappings, indicators of compromise, and defensive recommendations.
Download the Threat SnapshotFor a deeper analysis of the intrusion chain and malware behavior, read Blackpoint Cyber’s A Djinn in the Machine: TaskWeaver’s Node.js Intrusion Chain.
Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours