Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1059.007

T1059.007JavaScript

T1059.007 — JavaScript is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 156 detection use cases covering it and 97 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
156Use cases
97Articles
0Sub-techniques
1Tactic

Use cases covering this technique (156)

[WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Internal exploit · alerting DSΣPDDCS [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Internal install · alerting DSPDDCSCW [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Install-Time npm/Bun Lifecycle Execution Beaconing Out Within Minutes Internal install · alerting DSΣPDDCS [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Internal exploit · alerting DSΣPDD [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach Internal actions · alerting DSPDDCSCW [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] npm/node-gyp Install-Hook Spawn Chained to Outbound Egress Internal install · alerting DSΣPDDCS [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules Internal install · alerting DSΣPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain Internal install · alerting DSPDD [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) Internal install · alerting DSPDD [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s Internal install · alerting DSPDD [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start Internal c2 · alerting DSΣPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD Jscript Execution Using Cscript App ESCU actions · alerting P MS Scripting Process Loading Ldap Module ESCU actions · hunting P MS Scripting Process Loading WMI Module ESCU actions · hunting P Windows Cmdline Tool Execution From Non-Shell Process ESCU actions · hunting P Windows GrimResource - MMC Process Accessing APDS DLL ESCU actions · alerting P Cmdline Tool Not Executed In CMD Shell ESCU actions · alerting P [LLM] Node.js spawning shell/recon binaries or detached node -e loader Bespoke exploit · hunting DSΣPDDCS [LLM] Velocity.js SSTI RCE payload (constructor.constructor→child_process) in HTTP request Bespoke delivery · alerting SΣP [LLM] Vulnerable seroval (<=1.5.2) / TanStack Start (<1.167.30) exposure to CVE-2026-59940 deserialization RCE Bespoke exploit · hunting DS [LLM] NodeBB translation-token template-injection XSS in web request URI Bespoke exploit · alerting SΣP [LLM] NodeBB remote federated-user profile lookup (ActivityPub XSS #1 trigger) Bespoke delivery · hunting SΣP [LLM] NodeBB ActivityPub inbox POST carrying HTML-breakout id (Federation Errors stored XSS) Bespoke exploit · hunting SΣP [LLM] Detached hidden node.exe executing sync.js from NodeJS masquerade path Bespoke install · alerting DSΣPDDCS [LLM] npm/node install-time payload: package manager spawning curl/launchctl/osascript on a runner Bespoke exploit · hunting DSΣPCS [LLM] npm/node lifecycle script fetching Bun runtime from github.com/oven-sh/bun Bespoke install · alerting DSΣPDDCS [LLM] Malicious @bitwarden/cli payload artifacts on disk (bw_setup.js, bw1.js, Shai-Hulud markers) Bespoke install · alerting DSΣPDDCS [LLM] Broad reflected HTML/XSS payload tokens in MantisBT install.php query string Bespoke exploit · hunting SΣP [LLM] Malicious startup-module tiddler (.js.tid) written into a TiddlyWiki tiddlers/ directory Bespoke delivery · hunting DSΣPDDCS [LLM] Miasma/AsyncAPI first-stage: node spawns detached 'node -e' downloader referencing IPFS/sync.js Bespoke delivery · alerting DSΣPDDCS [LLM] Miasma stage-2 dropped: sync.js written to per-user NodeJS data directory Bespoke install · alerting DSΣPDDCS [LLM] Miasma stage-2 executed: node runs sync.js from NodeJS data directory Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud npm worm payload/workflow file drop (bundle.js, setup_bun.js, shai-hulud-workflow.yml) Bespoke install · hunting DSΣPDDCS [LLM] Sha1-Hulud 2.0 npm worm payload files (setup_bun.js / bun_environment.js) written or executed Bespoke install · hunting DSΣPDDCS [LLM] Ghost x-ghost-preview request carrying XSS payload markers (CVE-2026-53943 execution) Bespoke exploit · alerting SΣPDD [LLM] Phantom Gyp binding.gyp install-time payload execution (Miasma npm worm) Bespoke install · alerting DSΣPDDCS [LLM] Bun runtime executing a temp payload spawned by node (Miasma Node.js-monitoring evasion) Bespoke exploit · hunting DSΣPDDCS [LLM] Bun executes dropped temp payload /tmp/p*.js (Miasma stealer launch) Bespoke exploit · alerting DSΣPDDCS [LLM] Bun runtime executing payload index.js from semantic-release-action path Bespoke install · alerting DSΣPDDCS [LLM] easy-day-js npm postinstall dropper: node executing setup.cjs --no-warnings Bespoke install · alerting DSΣPDDCS [LLM] Bun runtime executing codfish/semantic-release-action index.js payload on CI runner Bespoke install · alerting DSΣPDDCS [LLM] Known Miasma index.js payload hash present on CI runner (codfish action) Bespoke delivery · alerting DS [LLM] Mastra easy-day-js postinstall dropper: node setup.cjs --no-warnings Bespoke install · alerting DSΣPDDCS [LLM] Miasma/Hades Bun dropper executed via npm/pip lifecycle hook (setup_bun.js / bun_environment.js) Bespoke install · alerting DSΣPDDCS [LLM] TruffleHog secret-scanning spawned by npm/pip during install (Shai-Hulud credential harvest) Bespoke actions · hunting DSΣPDDCS [LLM] Atomic Arch payload execution: JS runtime spawning shell/network tooling under AUR build (or known payload hash) Bespoke install · alerting DSPDDCS [LLM] Miasma/Hades auto-exec editor & AI-tool config files dropped in project tree Bespoke install · hunting DSΣPDDCS [LLM] Phantom Gyp: malicious binding.gyp executing during npm install Bespoke install · hunting DSΣPDDCS [LLM] Hades on-import payload: Python process spawning Bun JavaScript runtime Bespoke c2 · alerting DSΣPDDCS [LLM] easy-day-js postinstall dropper spawning node.exe with C2 IP passed as argument Bespoke install · alerting DSΣPDDCS [LLM] Malicious easy-day-js package installed into node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] Node.js writing a random 24-hex-char .js dropper to the OS temp directory Bespoke install · hunting DSΣPDDCS [LLM] npm install pulls malicious easy-day-js dropper (setup.cjs + .pkg marker files) Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud npm preinstall Bun bootstrap (setup_bun.js / bun_environment.js) Bespoke install · alerting DSΣPDDCS [LLM] TruffleHog secret-scan spawned by npm/node install (Shai-Hulud credential harvest) Bespoke actions · hunting DSΣPDDCS [LLM] Malicious 'postmark-mcp' MCP server package present/executing on developer endpoints Bespoke delivery · alerting DSΣPDDCS [LLM] Bun runtime executed from temp dir running _index.js payload (Hades Campaign) Bespoke install · alerting DSΣPDDCS [LLM] node.exe spawned by Code/Cursor/Claude/Gemini executing .github/setup.js Bespoke exploit · alerting DSΣPDDCS [LLM] Miasma Phantom Gyp: python.exe (gyp parser) spawning node index.js during npm install Bespoke install · alerting DSΣPDDCS [LLM] npm preinstall hook executing oversized node index.js from @redhat-cloud-services package Bespoke install · alerting DSΣPDDCS [LLM] Bun spawned from npm install context executing /tmp/p*.js implant Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud npm worm: postinstall bundle.js spawns TruffleHog secret scan Bespoke install · alerting DSΣPDDCS [LLM] Nx Console v18.95.0 Malicious Payload Bootstrap via Orphan Commit (npx github:nrwl/nx#558b09d7) Bespoke delivery · alerting DSΣPDDCS [LLM] Miasma worm index.js SHA256 IOC hit (Mini Shai-Hulud variant) Bespoke install · alerting DSΣPDDCS [LLM] npm preinstall hook spawns node index.js under @redhat-cloud-services package path Bespoke install · alerting DSΣPDDCS [LLM] npm/yarn/pnpm postinstall hook spawning credential-harvest tooling Bespoke install · hunting DSΣPDDCS [LLM] Trojanized axios npm package postinstall: node.exe spawned from plain-crypto-js dependency Bespoke install · alerting DSΣPDDCS [LLM] npm/pnpm install of trojanized codexui-android package on developer endpoint Bespoke delivery · hunting DSΣPDDCS [LLM] Nx Console v18.95.0 compromised extension installed (May 2026 supply-chain attack) Bespoke delivery · hunting DSΣPDDCS [LLM] TeamPCP Nx Console payload SHA256 hash match on developer endpoints Bespoke install · hunting DSΣPDDCS [LLM] VS Code child process fetching payload from nrwl/nx orphan commit (Nx Console v18.95.0 dropper) Bespoke install · alerting DSΣPDDCS [LLM] bun runtime executed on CI runner spawning python3 with sudo escalation Bespoke install · alerting DSΣPDDCS [LLM] Compromised node-ipc.cjs bundle write (~117KB) under node_modules Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud npm preinstall hook spawning bun runtime Bespoke install · alerting DSΣPDDCS [LLM] node-ipc stealer __ntw=1 environment marker in process command line Bespoke install · alerting DSΣPDDCS [LLM] FrostyNeighbor JS dropper self-relaunch with --update flag Bespoke exploit · alerting DSΣPDDCS [LLM] PicassoLoader scheduled-task creation by wscript/cscript after C2 XML fetch Bespoke install · alerting DSΣPDDCS [LLM] TeamPCP Mini Shai-Hulud stealer payload hash match (SHA256/SHA1) Bespoke install · alerting DSΣPDDCS [LLM] Bun spawned with tanstack_runner.js via npm prepare lifecycle (Mini Shai-Hulud) Bespoke install · alerting DSΣPDD [LLM] Mini Shai-Hulud Wave 4 (TanStack/TeamPCP) worm payload file created in node_modules Bespoke install · hunting DSΣPDD [LLM] Shai-Hulud npm preinstall: node spawns Bun runtime from bun-dl-* tmpdir Bespoke install · alerting DSΣPDD [LLM] Shai-Hulud known-bad setup.mjs / execution.js SHA256 hash match Bespoke install · alerting DSΣPDD [LLM] Bun runtime fetched from github.com/oven-sh/bun during npm install (Bitwarden CLI hijack) Bespoke delivery · alerting DSPDDCS [LLM] Known-malicious bw_setup.js / bw1.js SHA256 dropped under @bitwarden/cli Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud: Bun runtime executing `router_runtime.js` (2nd-stage stealer) Bespoke actions · alerting DSΣPDD [LLM] npm preinstall hook executes 'node setup.mjs' / 'bun execution.js' (Mini Shai-Hulud SAP supply chain) Bespoke install · alerting DSΣPDD [LLM] Mini Shai-Hulud known SHA256 IOC match (setup.mjs / execution.js / runner-memory dumper) Bespoke install · hunting DSΣPDD [LLM] Malicious tanstack npm postinstall hook executing postinstall.cjs Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud npm preinstall chain: node setup.mjs → bun execution.js Bespoke install · alerting DSΣPDD [LLM] Mailcow Autodiscover endpoint receives unauthenticated XSS payload (GHSA-f9xf-vc72-rcgm) Bespoke delivery · alerting SPDD [LLM] Mailcow quarantine XSS via EICAR + HTML in attachment filename (GHSA-2xjc-rg88-jvpp) Bespoke delivery · alerting DSΣPDD [LLM] Mailcow login with HTML/JS injected into X-Real-IP header (GHSA-jprq-w83q-q62h) Bespoke delivery · alerting SPDD [LLM] Shai-Hulud 2.0 npm worm artifact: setup_bun.js / bun_environment.js dropped by node/npm Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud preinstall: node/npm spawning git/curl/gh pushing to attacker repo or GitHub API Bespoke actions · hunting DSPDDCS [LLM] npm postinstall node setup.js dropper executing from plain-crypto-js with immediate network egress Bespoke install · alerting DSPDDCS [LLM] npm postinstall chain installs malicious 'openclaw' global package (cline@2.3.0 supply-chain IOC) Bespoke install · alerting DSΣPDDCS [LLM] GlassWorm Zig dropper native node addon (win.node/mac.node) written to IDE extension bin/ folder Bespoke install · hunting DSΣPDD [LLM] Hoppscotch Mock Server stored XSS via GraphQL updateRESTUserRequest content-type override Bespoke exploit · hunting DSPDD [LLM] npm postinstall hook spawning node init.js or child.js (React Native attack pattern) Bespoke install · alerting DSΣPDDCS [LLM] ForceMemo: init.json persistence file or i.js loader dropped by Python in user home root Bespoke install · hunting DSΣPDD [LLM] GlassWorm Stage-3 RAT installation under %APPDATA%\QtCvyfVWKH\index.js Bespoke install · alerting DSΣPDDCS [LLM] Four-way node.exe -e fanout spawned from VSCode shell descendants (BlokTrooper stage-2) Bespoke install · alerting DSPDDCS [LLM] DRILLAPP: Edge launched headless with media/security guardrails disabled Bespoke install · alerting DSΣPDDCS [LLM] DRILLAPP variant 2: Edge launched with --remote-debugging-port=9222 for CDP-based file download Bespoke c2 · alerting DSΣPDDCS [LLM] Installation of unauthorized cline@2.3.0 npm package on developer endpoints Bespoke delivery · alerting DSΣPDDCS [LLM] Install of Qix-compromised npm package@version (chalk 5.6.1, debug 4.4.2, ansi-styles 6.2.2 et al.) Bespoke install · alerting DSΣPDDCS [LLM] Scavenger npm supply chain: rundll32 executing node-gyp.dll from node_modules (CVE-2025-54313) Bespoke install · alerting DSΣPDD [LLM] Compromised npm package @vietmoney/react-big-calendar@0.26.2 installation (Shai-Hulud 3.0) Bespoke delivery · alerting DSΣPDDCS [LLM] npm/yarn/pnpm/bun lifecycle hook spawning shell or network LOLBin Bespoke install · hunting DSΣPDDCS [LLM] Anomalous POST to Next.js Server Action / RSC endpoint with 5xx error clustering Bespoke exploit · alerting DSPDDCS [LLM] SHA1-Hulud worm payload execution via npm preinstall (setup_bun.js / bun_environment.js) Bespoke install · alerting DSΣPDDCS [LLM] IndonesianFoods npm spam package install on developer/CI endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] IndonesianFoods auto-publish artifact (auto.js / publishScript.js) dropped in node_modules Bespoke install · alerting DSΣPDDCS [LLM] Installation or presence of malicious postmark-mcp npm package (v1.0.16+) Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud bundle.js postinstall payload by known SHA256 hash Bespoke install · hunting DSΣPDDCS [LLM] TruffleHog secret-scanner executed by node/npm postinstall context Bespoke actions · alerting DSΣPDDCS [LLM] Install / lockfile mention of the 28 compromised Qix-campaign package@versions Bespoke install · hunting DSΣPDDCS [LLM] Node/npm postinstall spawning AI coding agent CLI (s1ngularity execution chain) Bespoke install · alerting DSΣPDDCS [LLM] rundll32.exe loading node-gyp.dll dropped by Scavenger-infected npm postinstall (CVE-2025-54313) Bespoke install · alerting DSΣPDDCS [LLM] Browser/proxy fetch of compromised @lottiefiles/lottie-player from unpkg or jsDelivr CDN Bespoke delivery · alerting DSΣP [LLM] npm/yarn/pnpm install of himanshutester002 suspicious aliased packages (string-width-cjs et al) Bespoke delivery · alerting DSΣPDDCS [LLM] Jinja2 xmlattr XSS exploitation attempt in HTTP request parameters (CVE-2024-22195) Bespoke exploit · alerting SΣP [LLM] node-serialize / serialize-to-js deserialization RCE payload marker `_$$ND_FUNC$$_` in web request Bespoke exploit · alerting SP [LLM] node-ipc protestware dropper file 'ssl-geospec.js' written under node_modules\node-ipc Bespoke delivery · alerting DSΣPDDCS [LLM] Apache Commons Configuration interpolation RCE payload in HTTP requests (CVE-2022-33980) Bespoke exploit · hunting SΣP [LLM] Java (ProcessBuilder) spawning shell/LOLBin child — Commons Config interpolation RCE Bespoke install · alerting DSΣPDDCS [LLM] npm install-time script executing 'node .' postinstall payload Bespoke install · hunting DSΣPDDCS [LLM] npm post-install spawns node confsettingsaaa.js (gxm-reference dropper execution) Bespoke install · alerting DSΣPDDCS [LLM] Prototype pollution attempt via __proto__ in URL query string (CVE-2021-23682, litespeed.js/appwrite) Bespoke exploit · hunting SΣP [LLM] Prototype pollution / type-confusion payload in web request (__proto__, constructor[prototype]) Bespoke exploit · hunting SΣP [LLM] Node.js debugger/inspector launched bound to all network interfaces (CVE-2018-12120/-13567) Bespoke exploit · alerting DSΣPDDCS [LLM] Remote (non-loopback) connection to an exposed Node.js debug/inspect port 5858/9229 Bespoke exploit · alerting DSPDDCS [LLM] Installation of Snyk-flagged malicious npm packages (radar-cms, rcenodejs, paychex-*) Bespoke delivery · alerting DSΣPDDCS [LLM] npm postinstall executes node package-setup.js (crossenv env-var harvester) Bespoke install · alerting DSΣPDDCS [LLM] Grunt task-runner (node.exe) spawning a command shell — possible js-yaml load() ACE Bespoke exploit · hunting DSΣPDD [LLM] Install of malicious npm package versions angular-bmap@0.0.9 / ng-ui-library@1.0.987 Bespoke delivery · alerting DSΣPDDCS [LLM] Exposure: jackson-databind <=2.9.9.2 / Spring Boot 2.1.7 vulnerable to CVE-2019-14379/14439 deserialization RCE Bespoke exploit · alerting DSP [LLM] Malicious npm package electron-native-notify present in node_modules Bespoke install · alerting DSΣPDDCS [LLM] Build-time injection into vendored @zxing ReedSolomonDecoder.js (Copay wallet stealer payload) Bespoke install · alerting DSΣPDDCS [LLM] Malicious npm flatmap-stream / event-stream@3.3.6 dependency dropped to endpoint disk Bespoke delivery · alerting DSΣPDDCS [LLM] Dust.js qs type-manipulation RCE payload in web request query string Bespoke exploit · alerting SΣP [LLM] marked Markdown XSS sanitizer bypass — entity-encoded 'javascript&#58' payload in web requests Bespoke exploit · hunting DSΣPCS

Articles citing this technique (97)