JSFireTruck: Exploring Malicious JavaScript Using JSF*ck as an Obfuscation Technique
ID: 9c20a30f-ba54-5457-8307-66b811582372
STIX ID: report--9c20a30f-ba54-5457-8307-66b811582372
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-06-12
Date Updated: 2026-04-28
Author: Hardik Shah, Brad Duncan and Pranay Kumar Chhaparwal
This report analyzes a large-scale campaign that injects JSFireTruck (JSFuck)-obfuscated JavaScript into legitimate websites to silently redirect visitors (especially those referred by search engines) into malicious iframes that serve malware, malvertising, or fraudulent downloads; it includes technical deobfuscation, telemetry (≈269,552 infected pages over a one-month window), example IoCs (25 SHA256 hashes), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
