Symantec documents attackers abusing signed node.exe to run JavaScript payloads in intrusions since February.