JS-Tap: Weaponizing JavaScript for Red Teams
ID: 2117be75-60c3-5f7a-9e4e-161a9e2c696d
STIX ID: report--2117be75-60c3-5f7a-9e4e-161a9e2c696d
Feed Name: TrustedSec blog
JS-Tap is a malicious JavaScript payload and web portal designed to instrument client-side web applications to capture credentials, tokens, cookies (non-httponly), local/session storage, page HTML, screenshots, and intercepted XHR/Fetch network calls. The tool supports two deployment modes—Trap Mode (iframe-based persistence for transient XSS executions) and Implant Mode (injecting the payload into site-wide JavaScript files)—and includes features to monkeypatch network APIs to exfiltrate authorization headers, request and response bodies, and take delayed screenshots. The report walks through WordPress and single-page application demos, showing how JS-Tap collects loot and presents it in a management portal.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
