<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #JavaScript</title><description>Cybersecurity articles tagged #JavaScript on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Polymorphic Phishing Page Analysis: JavaScript Obfuscation Flaws</title><link>https://runtimerebel.com/blog/polymorphic-phishing-page-analysis-javascript-obfuscation-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/polymorphic-phishing-page-analysis-javascript-obfuscation-flaws</guid><description>Analysis of a polymorphic phishing page utilizing heavy JavaScript obfuscation and variable scope bugs that cause browser loops.</description><pubDate>Tue, 01 Sep 2026 02:51:10 GMT</pubDate><category>Phishing</category><category>Credential Theft</category><category>Obfuscation</category><category>JavaScript</category><category>Malware Analysis</category></item><item><title>Deobfuscating Malicious JavaScript for Threat Analysis</title><link>https://runtimerebel.com/blog/deobfuscating-malicious-javascript-for-threat-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/deobfuscating-malicious-javascript-for-threat-analysis</guid><description>Understanding JavaScript obfuscation techniques used in phishing and malware. Learn static and dynamic deobfuscation methods to uncover malicious intent.</description><pubDate>Tue, 01 Sep 2026 02:45:47 GMT</pubDate><category>JavaScript</category><category>Obfuscation</category><category>Phishing</category><category>Malware</category><category>Deobfuscation</category></item><item><title>ChainDrop npm Supply Chain Attack Steals Developer Credentials</title><link>https://runtimerebel.com/blog/chaindrop-npm-supply-chain-attack-steals-developer-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/chaindrop-npm-supply-chain-attack-steals-developer-credentials</guid><description>Massive ChainDrop npm supply chain attack compromises over 1,300 packages, stealing developer and cloud credentials through malicious preinstall scripts.</description><pubDate>Tue, 04 Aug 2026 17:30:58 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>JavaScript</category><category>ChainDrop</category></item><item><title>Adform Script Poisoning: Crypto Wallet Swapping Attack</title><link>https://runtimerebel.com/blog/adform-script-poisoning-crypto-wallet-swapping-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/adform-script-poisoning-crypto-wallet-swapping-attack</guid><description>Adform&apos;s JavaScript was poisoned to swap crypto wallet addresses on customer sites.</description><pubDate>Sat, 01 Aug 2026 10:00:39 GMT</pubDate><category>Adform</category><category>JavaScript</category><category>Cryptocurrency</category><category>Wallet Swapping</category><category>Supply Chain Attack</category><category>Client Side Attack</category></item><item><title>&quot;Adblock for YouTube&quot; Extension: Dormant Script Injection Threat</title><link>https://runtimerebel.com/blog/adblock-for-youtube-extension-dormant-script-injection-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/adblock-for-youtube-extension-dormant-script-injection-threat</guid><description>A popular Chrome ad blocker, &quot;Adblock for YouTube,&quot; with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection.</description><pubDate>Thu, 25 Jun 2026 17:17:00 GMT</pubDate><category>Chrome Extension</category><category>Adblock for YouTube</category><category>Script Injection</category><category>JavaScript</category><category>Browser Security</category><category>Supply Chain</category><category>Malicious Extension</category></item><item><title>Malicious npm Packages Impersonate PostCSS to Deliver Windows RAT</title><link>https://runtimerebel.com/blog/malicious-npm-packages-impersonate-postcss-to-deliver-windows-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-npm-packages-impersonate-postcss-to-deliver-windows-rat</guid><description>Security researchers uncover malicious npm packages such as postcss-minify-selector-parser delivering Windows RATs via supply chain attacks. Audit your builds.</description><pubDate>Tue, 23 Jun 2026 13:10:31 GMT</pubDate><category>NPM</category><category>PostCSS</category><category>Typosquatting</category><category>RAT</category><category>JavaScript</category></item><item><title>IronWorm Malware: 36 npm Packages Identified in Supply Chain Attack</title><link>https://runtimerebel.com/blog/ironworm-malware-36-npm-packages-identified-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/ironworm-malware-36-npm-packages-identified-in-supply-chain-attack</guid><description>Security researchers discover a campaign delivering IronWorm infostealer malware via 36 malicious npm packages using preinstall script execution hooks.</description><pubDate>Thu, 04 Jun 2026 17:09:30 GMT</pubDate><category>NPM</category><category>IronWorm</category><category>Infostealer</category><category>Supply Chain Attack</category><category>JavaScript</category></item><item><title>NetSupport RAT Infection: How to Detect Unidentified Loader Exploits</title><link>https://runtimerebel.com/blog/netsupport-rat-infection-how-to-detect-unidentified-loader-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/netsupport-rat-infection-how-to-detect-unidentified-loader-exploits</guid><description>Analyze the multi-stage infection chain of an unidentified loader delivering NetSupport RAT, featuring technical breakdowns of JavaScript and PowerShell TTPs.</description><pubDate>Mon, 01 Jun 2026 01:04:07 GMT</pubDate><category>NetSupport RAT</category><category>Malware Analysis</category><category>PowerShell</category><category>JavaScript</category><category>Loader</category></item><item><title>Chromium RCE Risk: Unfixed Flaw Allows Background JavaScript</title><link>https://runtimerebel.com/blog/chromium-rce-risk-unfixed-flaw-allows-background-javascript</link><guid isPermaLink="true">https://runtimerebel.com/blog/chromium-rce-risk-unfixed-flaw-allows-background-javascript</guid><description>Google accidentally exposed details of an unfixed Chromium flaw. This enables RCE via persistent background JavaScript execution, affecting many browsers.</description><pubDate>Thu, 21 May 2026 20:40:55 GMT</pubDate><category>Chromium</category><category>RCE</category><category>JavaScript</category><category>Browser Security</category><category>Google</category><category>Zero-Day</category></item><item><title>320+ @antv NPM Packages Compromised in Mini Shai-Hulud Attack</title><link>https://runtimerebel.com/blog/320-antv-npm-packages-compromised-in-mini-shai-hulud-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/320-antv-npm-packages-compromised-in-mini-shai-hulud-attack</guid><description>A maintainer account compromise has led to a major supply chain attack against Alibaba’s @antv NPM namespace, impacting over 320 visualization packages.</description><pubDate>Wed, 20 May 2026 13:06:33 GMT</pubDate><category>NPM</category><category>Mini Shai Hulud</category><category>Antv</category><category>Supply Chain Security</category><category>JavaScript</category></item><item><title>Malicious PDF Files: Analyzing AcroForm JavaScript for Initial Access</title><link>https://runtimerebel.com/blog/malicious-pdf-files-analyzing-acroform-javascript-for-initial-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-pdf-files-analyzing-acroform-javascript-for-initial-access</guid><description>Security analysts have identified malicious PDF files utilizing AcroForm dictionaries to execute JavaScript and fetch remote payloads from external servers.</description><pubDate>Mon, 04 May 2026 05:14:53 GMT</pubDate><category>PDF Malware</category><category>AcroForm</category><category>JavaScript</category><category>Initial Access</category><category>Adobe Reader</category></item><item><title>Detect Obfuscated JavaScript Phishing Delivered via RAR Archives</title><link>https://runtimerebel.com/blog/detect-obfuscated-javascript-phishing-delivered-via-rar-archives</link><guid isPermaLink="true">https://runtimerebel.com/blog/detect-obfuscated-javascript-phishing-delivered-via-rar-archives</guid><description>Security researchers identify a new phishing campaign using heavily obfuscated JavaScript within RAR archives to bypass traditional endpoint detection.</description><pubDate>Fri, 10 Apr 2026 08:43:36 GMT</pubDate><category>JavaScript</category><category>Phishing</category><category>RAR</category><category>Obfuscation</category><category>WScript</category><category>Evasion</category></item><item><title>Magecart Skimmer Hides in Pixel-Sized SVG on Magento Stores</title><link>https://runtimerebel.com/blog/magecart-skimmer-hides-in-pixel-sized-svg-on-magento-stores</link><guid isPermaLink="true">https://runtimerebel.com/blog/magecart-skimmer-hides-in-pixel-sized-svg-on-magento-stores</guid><description>A sophisticated Magecart campaign targets nearly 100 Magento stores, concealing credit card-stealing JavaScript within tiny, pixel-sized SVG images.</description><pubDate>Thu, 09 Apr 2026 00:34:13 GMT</pubDate><category>Magecart</category><category>Credit Card Skimmer</category><category>Magento</category><category>E Commerce</category><category>SVG</category><category>JavaScript</category><category>Supply Chain Attack</category></item><item><title>BrowserGate: LinkedIn&apos;s Stealthy Chrome Extension Scanning and Data Collection</title><link>https://runtimerebel.com/blog/browsergate-linkedin-s-stealthy-chrome-extension-scanning-and-data-collection</link><guid isPermaLink="true">https://runtimerebel.com/blog/browsergate-linkedin-s-stealthy-chrome-extension-scanning-and-data-collection</guid><description>Analysis of &apos;BrowserGate&apos; reveals LinkedIn&apos;s hidden JavaScript scanning over 6,000 Chrome extensions and collecting user device data. Understand the privacy implications.</description><pubDate>Sat, 04 Apr 2026 00:37:09 GMT</pubDate><category>LinkedIn</category><category>BrowserGate</category><category>Chrome Extensions</category><category>Data Collection</category><category>Privacy</category><category>JavaScript</category></item><item><title>Axios NPM Compromise: Supply Chain Threat Analysis</title><link>https://runtimerebel.com/blog/axios-npm-compromise-supply-chain-threat-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-compromise-supply-chain-threat-analysis</guid><description>Analysis of the Axios NPM package compromise, a potential supply chain attack impacting JavaScript HTTP client library users, possibly by North Korean threat actors.</description><pubDate>Wed, 01 Apr 2026 00:44:25 GMT</pubDate><category>Axios</category><category>NPM</category><category>JavaScript</category><category>Supply Chain Attack</category><category>Threat Actors</category></item><item><title>Axios npm Package Hijacked: Cross-Platform Malware Distribution</title><link>https://runtimerebel.com/blog/axios-npm-package-hijacked-cross-platform-malware-distribution</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-package-hijacked-cross-platform-malware-distribution</guid><description>Analysis of the Axios npm package hijack distributing remote access trojans to Linux, Windows, and macOS systems. Learn to protect your software supply chain.</description><pubDate>Tue, 31 Mar 2026 16:29:10 GMT</pubDate><category>Axios</category><category>NPM</category><category>Supply Chain Attack</category><category>Remote Access Trojan</category><category>Malware</category><category>JavaScript</category><category>Linux</category><category>Windows</category><category>macOS</category></item><item><title>SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft</title><link>https://runtimerebel.com/blog/sandworm-mode-malicious-npm-cluster-automates-secret-harvesting-and-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/sandworm-mode-malicious-npm-cluster-automates-secret-harvesting-and-crypto-theft</guid><description>Security researchers have identified a coordinated campaign involving 19 malicious npm packages designed to exfiltrate CI/CD secrets, API tokens, and private…</description><pubDate>Mon, 23 Feb 2026 12:20:23 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Credential Harvesting</category><category>CI CD Security</category><category>JavaScript</category></item><item><title>Malicious npm Package Targets React Developers with Backdoored Polyfill</title><link>https://runtimerebel.com/blog/supply-chain-attack-npm</link><guid isPermaLink="true">https://runtimerebel.com/blog/supply-chain-attack-npm</guid><description>A typosquatted npm package mimicking a popular React utility has been downloaded over 47,000 times before removal.</description><pubDate>Thu, 25 Jan 2024 00:00:00 GMT</pubDate><category>NPM</category><category>Supply Chain</category><category>Typosquatting</category><category>JavaScript</category><category>Backdoor</category></item></channel></rss>