The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time
ID: 817696ec-6e7c-53d5-af31-0ceaa2a977f2
STIX ID: report--817696ec-6e7c-53d5-af31-0ceaa2a977f2
Feed Name: Palo Alto Networks Unit 42
Date Published: 2026-01-22
Date Updated: 2026-04-28
Author: Shehroze Farooqi, Alex Starov, Diva-Oriane Marty and Billy Melicher
This report describes a proof-of-concept attack where an apparently benign webpage calls trusted LLM APIs from the client side to generate malicious JavaScript snippets at runtime, assembling polymorphic phishing pages in the victim's browser that evade network-based detection; it details the PoC steps, evasion advantages, alternative delivery methods, and mitigation recommendations emphasizing in-browser runtime behavioral analysis and stricter LLM guardrails.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
