Skip to main content

Threats Tagged 'javascript'

View all threats tagged with 'javascript'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: javascript

Threats Tagged 'javascript'

Click on any threat for detailed analysis and mitigation recommendations

A malicious NPM package named indexed-btree, impersonating the legitimate sorted-btree package, was discovered to contain hidden malware in its JavaScript prototype method. This supply chain attack accumulated over 2 million weekly downloads by creating a credible GitHub repository and avoiding typical detection methods. The malware collects system information, communicates with a hardcoded Slack channel and Telegram chat, and uses a blockchain smart contract for command-and-control. Multiple related malicious packages have also been identified and removed after millions of downloads. The campaign is ongoing and represents a sophisticated threat to organizations using the NPM ecosystem.

Join the discussion

A malware campaign involving the npm package 'indexed-btree' demonstrates how attackers evade traditional supply chain defenses by embedding malicious code in the package's runtime behavior instead of installation scripts. This technique allows the malware to bypass install-time security checks and execute malicious actions during normal package usage.

Join the discussion

Brevo experienced a supply-chain attack where attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into Brevo's websites and JavaScript files embedded on customer sites. This injection was used to distribute malware to visitors of affected sites.

Join the discussion

CVE-2026-84942 is a high-severity cross-site scripting (XSS) vulnerability in AWS Amazon OpenSearch Service affecting the Vega expression function implementation in OpenSearch Dashboards. It allows a remote authenticated user with dashboard write permissions to execute arbitrary JavaScript in other users' browsers by saving a specially crafted Vega visualization. The vulnerability arises because the input validation routine failed to properly inspect nested arrays, allowing malicious function properties to bypass checks. This can lead to complete compromise of user sessions without impacting availability.

Join the discussion

Cisco Talos identified a malware infection chain involving WebDAV-based DLL execution delivering the Amatera stealer and secondary payloads including ZigCryptoStealer and NetSupport Manager. The infection chain uses a Cloudflare Worker to inject JavaScript stored on BNB Smart Chain and a fake CAPTCHA prompt to trick victims into executing the malware. Two distinct DLL loaders named "verification.google" and "pf.ch" were observed, each deploying different secondary payloads. The "verification.google" loader installed NetSupport Manager with a command-and-control server IP linked to Russia, suggesting a Russian threat actor. The infection was first observed in April 2026 targeting a Ukrainian government organization but is assessed as not specifically targeted. Multiple infection chains delivering Amatera stealer have been documented, but no direct infrastructure links were found between them. The threat involves credential and cryptocurrency theft through sophisticated multi-stage delivery mechanisms.

Join the discussion

Cisco Talos is tracking a cryptocurrency theft campaign that abuses the Google Visualization API to deliver obfuscated JavaScript from Google Sheets, which victims are socially engineered to inject into their browser sessions. The attack uses a variation of ClickFix social engineering, convincing targets to paste malicious JavaScript into the Chrome address bar or install it via the Tampermonkey extension for persistence. The malicious script acts as a web skimmer, hooking the browser's fetch API to replace cryptocurrency deposit addresses and manipulate clipboard contents, deceiving users with fake bonus interfaces. The campaign targets users on cryptocurrency and hacking forums with a lure about a nonexistent API vulnerability to entice quick financial gain. The actors moved their hosting to Google Docs and Sheets after disruptions on paste sites. While this campaign primarily targets individuals, the techniques used could be adapted for broader supply-chain or web-based attacks.

Join the discussion

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry in a crafted .ownership-file. Version 0.3.156 removes shell interpretation of the owner field, running the command directly rather than through a shell, and rejects values outside an allowlisted command form. This eliminates shell metacharacter command injection. To remediate this issue, users should upgrade to version 0.3.156 or later. No action is required for use of the Amazon CodeCatalyst service. Resynthesis runs in an isolated per-project environment with scoped credentials, and the service applies server-side validation there that rejects [local] merge strategy commands outside a restricted allowlisted form, including for blueprint versions published before 0.3.156.

Join the discussion

JSCeal is a sophisticated cryptocurrency-focused stealer malware delivered as compiled V8 bytecode executed by a bundled Node.js runtime. It uses multiple layers of JavaScript obfuscation and compilation to evade analysis. The malware includes capabilities such as keylogging, browser and credential theft, screenshot capture, and HTTPS traffic interception via a local man-in-the-middle proxy. Check Point Research developed a static deobfuscation pipeline to analyze JSCeal without execution, enabling detailed understanding of its behavior and evolution. The malware targets multiple platforms including macOS and continues to evolve with new payload encryption and targeting techniques.

Join the discussion

Two men in Australia were arrested for their alleged involvement in TeamPCP, a cybercrime syndicate responsible for extensive software supply chain attacks. TeamPCP embedded malicious code in numerous open source software tools, compromising thousands of global businesses. The group used a self-propagating worm called Shai-Hulud to infect open source projects and steal developer credentials, enabling further malicious code insertion. They also ran a contest to recruit additional hackers by incentivizing supply chain compromises. Their attacks included targeting AI infrastructure via the LiteLLM open source AI gateway, harvesting cloud service keys from over 2,500 organizations. TeamPCP compromised thousands of code repositories on GitHub by exploiting compromised developer tools. The group appears to be a loose coalition of multiple cybercriminal actors rather than a single structured entity.

Join the discussion

This analysis covers the use of JavaScript obfuscation techniques commonly found in phishing kits, malware loaders, and other malicious scripts. Obfuscation transforms JavaScript code to hide its true intent by encoding strings, renaming functions, and using runtime decoding, making manual analysis difficult. While obfuscation can be used for legitimate purposes such as performance optimization or IP protection, it is frequently employed to conceal malicious behavior like credential theft and malware delivery. The article emphasizes that beautifying code is insufficient to fully understand obfuscated scripts, as it does not restore original logic or decode runtime-generated content. Analysts should treat such samples as hostile and avoid executing them in unsafe environments. The post provides definitions and examples of obfuscation techniques and discusses approaches to analyzing these challenging scripts.

Join the discussion

Showing 1 to 10 of 66 results

Filters:Tag: javascript
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses