InvisibleJS Tool Hides Executable ES Modules in Empty Files Using Zero-Width Steganography
ID: 16557075-64c9-5fed-b102-104821c238a9
STIX ID: report--16557075-64c9-5fed-b102-104821c238a9
Feed Name: cybersecurityNews.com
This report examines InvisibleJS, an open-source project that conceals JavaScript by converting code to binary and mapping bits to Zero Width Space (U+200B) and Zero Width Non-Joiner (U+200C), then decoding and executing it at runtime via a bootstrap loader; it presents two variants (Classic with eval for CommonJS and Modern with dynamic import for ESM), usage examples, and a feature comparison, while stressing that similar Unicode-based obfuscation has been abused in phishing and malware loaders and urging defenders to implement Unicode-aware scanning and behavioral detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
