T1059.007JavaScript
T1059.007 — JavaScript is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 156 detection use cases covering it and 97 threat-intel articles citing it.
Execution
156Use cases
97Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (156)
[WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes [WEEKLY] Install-Time npm/Bun Lifecycle Execution Beaconing Out Within Minutes [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) [WEEKLY] npm/node-gyp Install-Hook Spawn Chained to Outbound Egress [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Jscript Execution Using Cscript App MS Scripting Process Loading Ldap Module MS Scripting Process Loading WMI Module Windows Cmdline Tool Execution From Non-Shell Process Windows GrimResource - MMC Process Accessing APDS DLL Cmdline Tool Not Executed In CMD Shell [LLM] Node.js spawning shell/recon binaries or detached node -e loader [LLM] Velocity.js SSTI RCE payload (constructor.constructor→child_process) in HTTP request [LLM] Vulnerable seroval (<=1.5.2) / TanStack Start (<1.167.30) exposure to CVE-2026-59940 deserialization RCE [LLM] NodeBB translation-token template-injection XSS in web request URI [LLM] NodeBB remote federated-user profile lookup (ActivityPub XSS #1 trigger) [LLM] NodeBB ActivityPub inbox POST carrying HTML-breakout id (Federation Errors stored XSS) [LLM] Detached hidden node.exe executing sync.js from NodeJS masquerade path [LLM] npm/node install-time payload: package manager spawning curl/launchctl/osascript on a runner [LLM] npm/node lifecycle script fetching Bun runtime from github.com/oven-sh/bun [LLM] Malicious @bitwarden/cli payload artifacts on disk (bw_setup.js, bw1.js, Shai-Hulud markers) [LLM] Broad reflected HTML/XSS payload tokens in MantisBT install.php query string [LLM] Malicious startup-module tiddler (.js.tid) written into a TiddlyWiki tiddlers/ directory [LLM] Miasma/AsyncAPI first-stage: node spawns detached 'node -e' downloader referencing IPFS/sync.js [LLM] Miasma stage-2 dropped: sync.js written to per-user NodeJS data directory [LLM] Miasma stage-2 executed: node runs sync.js from NodeJS data directory [LLM] Shai-Hulud npm worm payload/workflow file drop (bundle.js, setup_bun.js, shai-hulud-workflow.yml) [LLM] Sha1-Hulud 2.0 npm worm payload files (setup_bun.js / bun_environment.js) written or executed [LLM] Ghost x-ghost-preview request carrying XSS payload markers (CVE-2026-53943 execution) [LLM] Phantom Gyp binding.gyp install-time payload execution (Miasma npm worm) [LLM] Bun runtime executing a temp payload spawned by node (Miasma Node.js-monitoring evasion) [LLM] Bun executes dropped temp payload /tmp/p*.js (Miasma stealer launch) [LLM] Bun runtime executing payload index.js from semantic-release-action path [LLM] easy-day-js npm postinstall dropper: node executing setup.cjs --no-warnings [LLM] Bun runtime executing codfish/semantic-release-action index.js payload on CI runner [LLM] Known Miasma index.js payload hash present on CI runner (codfish action) [LLM] Mastra easy-day-js postinstall dropper: node setup.cjs --no-warnings [LLM] Miasma/Hades Bun dropper executed via npm/pip lifecycle hook (setup_bun.js / bun_environment.js) [LLM] TruffleHog secret-scanning spawned by npm/pip during install (Shai-Hulud credential harvest) [LLM] Atomic Arch payload execution: JS runtime spawning shell/network tooling under AUR build (or known payload hash) [LLM] Miasma/Hades auto-exec editor & AI-tool config files dropped in project tree [LLM] Phantom Gyp: malicious binding.gyp executing during npm install [LLM] Hades on-import payload: Python process spawning Bun JavaScript runtime [LLM] easy-day-js postinstall dropper spawning node.exe with C2 IP passed as argument [LLM] Malicious easy-day-js package installed into node_modules [LLM] Node.js writing a random 24-hex-char .js dropper to the OS temp directory [LLM] npm install pulls malicious easy-day-js dropper (setup.cjs + .pkg marker files) [LLM] Shai-Hulud npm preinstall Bun bootstrap (setup_bun.js / bun_environment.js) [LLM] TruffleHog secret-scan spawned by npm/node install (Shai-Hulud credential harvest) [LLM] Malicious 'postmark-mcp' MCP server package present/executing on developer endpoints [LLM] Bun runtime executed from temp dir running _index.js payload (Hades Campaign) [LLM] node.exe spawned by Code/Cursor/Claude/Gemini executing .github/setup.js [LLM] Miasma Phantom Gyp: python.exe (gyp parser) spawning node index.js during npm install [LLM] npm preinstall hook executing oversized node index.js from @redhat-cloud-services package [LLM] Bun spawned from npm install context executing /tmp/p*.js implant [LLM] Shai-Hulud npm worm: postinstall bundle.js spawns TruffleHog secret scan [LLM] Nx Console v18.95.0 Malicious Payload Bootstrap via Orphan Commit (npx github:nrwl/nx#558b09d7) [LLM] Miasma worm index.js SHA256 IOC hit (Mini Shai-Hulud variant) [LLM] npm preinstall hook spawns node index.js under @redhat-cloud-services package path [LLM] npm/yarn/pnpm postinstall hook spawning credential-harvest tooling [LLM] Trojanized axios npm package postinstall: node.exe spawned from plain-crypto-js dependency [LLM] npm/pnpm install of trojanized codexui-android package on developer endpoint [LLM] Nx Console v18.95.0 compromised extension installed (May 2026 supply-chain attack) [LLM] TeamPCP Nx Console payload SHA256 hash match on developer endpoints [LLM] VS Code child process fetching payload from nrwl/nx orphan commit (Nx Console v18.95.0 dropper) [LLM] bun runtime executed on CI runner spawning python3 with sudo escalation [LLM] Compromised node-ipc.cjs bundle write (~117KB) under node_modules [LLM] Mini Shai-Hulud npm preinstall hook spawning bun runtime [LLM] node-ipc stealer __ntw=1 environment marker in process command line [LLM] FrostyNeighbor JS dropper self-relaunch with --update flag [LLM] PicassoLoader scheduled-task creation by wscript/cscript after C2 XML fetch [LLM] TeamPCP Mini Shai-Hulud stealer payload hash match (SHA256/SHA1) [LLM] Bun spawned with tanstack_runner.js via npm prepare lifecycle (Mini Shai-Hulud) [LLM] Mini Shai-Hulud Wave 4 (TanStack/TeamPCP) worm payload file created in node_modules [LLM] Shai-Hulud npm preinstall: node spawns Bun runtime from bun-dl-* tmpdir [LLM] Shai-Hulud known-bad setup.mjs / execution.js SHA256 hash match [LLM] Bun runtime fetched from github.com/oven-sh/bun during npm install (Bitwarden CLI hijack) [LLM] Known-malicious bw_setup.js / bw1.js SHA256 dropped under @bitwarden/cli [LLM] Mini Shai-Hulud: Bun runtime executing `router_runtime.js` (2nd-stage stealer) [LLM] npm preinstall hook executes 'node setup.mjs' / 'bun execution.js' (Mini Shai-Hulud SAP supply chain) [LLM] Mini Shai-Hulud known SHA256 IOC match (setup.mjs / execution.js / runner-memory dumper) [LLM] Malicious tanstack npm postinstall hook executing postinstall.cjs [LLM] Mini Shai-Hulud npm preinstall chain: node setup.mjs → bun execution.js [LLM] Mailcow Autodiscover endpoint receives unauthenticated XSS payload (GHSA-f9xf-vc72-rcgm) [LLM] Mailcow quarantine XSS via EICAR + HTML in attachment filename (GHSA-2xjc-rg88-jvpp) [LLM] Mailcow login with HTML/JS injected into X-Real-IP header (GHSA-jprq-w83q-q62h) [LLM] Shai-Hulud 2.0 npm worm artifact: setup_bun.js / bun_environment.js dropped by node/npm [LLM] Shai-Hulud preinstall: node/npm spawning git/curl/gh pushing to attacker repo or GitHub API [LLM] npm postinstall node setup.js dropper executing from plain-crypto-js with immediate network egress [LLM] npm postinstall chain installs malicious 'openclaw' global package (cline@2.3.0 supply-chain IOC) [LLM] GlassWorm Zig dropper native node addon (win.node/mac.node) written to IDE extension bin/ folder [LLM] Hoppscotch Mock Server stored XSS via GraphQL updateRESTUserRequest content-type override [LLM] npm postinstall hook spawning node init.js or child.js (React Native attack pattern) [LLM] ForceMemo: init.json persistence file or i.js loader dropped by Python in user home root [LLM] GlassWorm Stage-3 RAT installation under %APPDATA%\QtCvyfVWKH\index.js [LLM] Four-way node.exe -e fanout spawned from VSCode shell descendants (BlokTrooper stage-2) [LLM] DRILLAPP: Edge launched headless with media/security guardrails disabled [LLM] DRILLAPP variant 2: Edge launched with --remote-debugging-port=9222 for CDP-based file download [LLM] Installation of unauthorized cline@2.3.0 npm package on developer endpoints [LLM] Install of Qix-compromised npm package@version (chalk 5.6.1, debug 4.4.2, ansi-styles 6.2.2 et al.) [LLM] Scavenger npm supply chain: rundll32 executing node-gyp.dll from node_modules (CVE-2025-54313) [LLM] Compromised npm package @vietmoney/react-big-calendar@0.26.2 installation (Shai-Hulud 3.0) [LLM] npm/yarn/pnpm/bun lifecycle hook spawning shell or network LOLBin [LLM] Anomalous POST to Next.js Server Action / RSC endpoint with 5xx error clustering [LLM] SHA1-Hulud worm payload execution via npm preinstall (setup_bun.js / bun_environment.js) [LLM] IndonesianFoods npm spam package install on developer/CI endpoint [LLM] IndonesianFoods auto-publish artifact (auto.js / publishScript.js) dropped in node_modules [LLM] Installation or presence of malicious postmark-mcp npm package (v1.0.16+) [LLM] Shai-Hulud bundle.js postinstall payload by known SHA256 hash [LLM] TruffleHog secret-scanner executed by node/npm postinstall context [LLM] Install / lockfile mention of the 28 compromised Qix-campaign package@versions [LLM] Node/npm postinstall spawning AI coding agent CLI (s1ngularity execution chain) [LLM] rundll32.exe loading node-gyp.dll dropped by Scavenger-infected npm postinstall (CVE-2025-54313) [LLM] Browser/proxy fetch of compromised @lottiefiles/lottie-player from unpkg or jsDelivr CDN [LLM] npm/yarn/pnpm install of himanshutester002 suspicious aliased packages (string-width-cjs et al) [LLM] Jinja2 xmlattr XSS exploitation attempt in HTTP request parameters (CVE-2024-22195) [LLM] node-serialize / serialize-to-js deserialization RCE payload marker `_$$ND_FUNC$$_` in web request [LLM] node-ipc protestware dropper file 'ssl-geospec.js' written under node_modules\node-ipc [LLM] Apache Commons Configuration interpolation RCE payload in HTTP requests (CVE-2022-33980) [LLM] Java (ProcessBuilder) spawning shell/LOLBin child — Commons Config interpolation RCE [LLM] npm install-time script executing 'node .' postinstall payload [LLM] npm post-install spawns node confsettingsaaa.js (gxm-reference dropper execution) [LLM] Prototype pollution attempt via __proto__ in URL query string (CVE-2021-23682, litespeed.js/appwrite) [LLM] Prototype pollution / type-confusion payload in web request (__proto__, constructor[prototype]) [LLM] Node.js debugger/inspector launched bound to all network interfaces (CVE-2018-12120/-13567) [LLM] Remote (non-loopback) connection to an exposed Node.js debug/inspect port 5858/9229 [LLM] Installation of Snyk-flagged malicious npm packages (radar-cms, rcenodejs, paychex-*) [LLM] npm postinstall executes node package-setup.js (crossenv env-var harvester) [LLM] Grunt task-runner (node.exe) spawning a command shell — possible js-yaml load() ACE [LLM] Install of malicious npm package versions angular-bmap@0.0.9 / ng-ui-library@1.0.987 [LLM] Exposure: jackson-databind <=2.9.9.2 / Spring Boot 2.1.7 vulnerable to CVE-2019-14379/14439 deserialization RCE [LLM] Malicious npm package electron-native-notify present in node_modules [LLM] Build-time injection into vendored @zxing ReedSolomonDecoder.js (Copay wallet stealer payload) [LLM] Malicious npm flatmap-stream / event-stream@3.3.6 dependency dropped to endpoint disk [LLM] Dust.js qs type-manipulation RCE payload in web request query string [LLM] marked Markdown XSS sanitizer bypass — entity-encoded 'javascript:' payload in web requestsArticles citing this technique (97)
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-316
high Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files art-317
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-412
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-431
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-440
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-471
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-556
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-590
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
high Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182) art-753