THREAT OPS › Threat News › JavaScript obfuscation: From party trick to phishing kit
JavaScript obfuscation: From party trick to phishing kit
<img alt="JavaScript obfuscation: From party trick to phishing kit" src="https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/08/tool_talk.jpg" /><p>We open a JavaScript artifact hoping for code, and instead get string arrays, strangely named functions, encoded URLs, runtime decoders, and eval statements. That is the point where “reading the scriptȁ
MITRE ATT&CK techniques
Indicators of compromise
- http://biomejs.dev/url
- https://prettier.io/url
- https://"`url
- https://"url
- https://example.com"url
- https://esolangs.org/wiki/BrainFuckurl
- https://esolangs.org/wiki/JSFuckurl
- https://www.w3schools.com/js/js_type_coercion.aspurl
- storage.ghost.iodomain
- obfuscator.iodomain