Skip to content
Breaking
Jakarta stocks rise as political risks ease, BI leadership takes shapeTNB and Petronas launch RM10 billion green energy partnershipSaravanan admits to taking almost RM1.1 million in bribesKak Kay’s personality framework helps couples decode relationship conflictsNepal floods trap 55 Malaysians, including two senior rescue officersSaravanan charged with receiving RM1.097m bribe, foreign worker quota application approvedJakarta protests force road closures, leaving Malaysians strandedNepal police release names of 23 missing Malaysians after floodsMerdeka Weekend, Sorted: Party, Chill & Everything In BetweenViu Original 'Cela' hits No 1 on Viu charts in first weekWhat to expect on Bursa Malaysia this FridaySaravanan arrives at court, faces corruption chargesCarbon market framework to unlock RM560 million a year in climate financeU.S.-Canada trade talks collapse as Trump prepares 50% tariffs on autos and steelIran war at six months leaves Strait of Hormuz disrupted and U.S. facing strategic setbackMistrust threatens Bersatu-PH pact for Melaka pollsKennedy Center board’s Trump renaming rush questioned by US judgeUN condemns US labeling Palestine Action as extremist groupSyria’s president appoints ex-commander of Kurdish-led SDF as advisorHKEX posts record first-half profit as mainland tech listings fuel growthJakarta stocks rise as political risks ease, BI leadership takes shapeTNB and Petronas launch RM10 billion green energy partnershipSaravanan admits to taking almost RM1.1 million in bribesKak Kay’s personality framework helps couples decode relationship conflictsNepal floods trap 55 Malaysians, including two senior rescue officersSaravanan charged with receiving RM1.097m bribe, foreign worker quota application approvedJakarta protests force road closures, leaving Malaysians strandedNepal police release names of 23 missing Malaysians after floodsMerdeka Weekend, Sorted: Party, Chill & Everything In BetweenViu Original 'Cela' hits No 1 on Viu charts in first weekWhat to expect on Bursa Malaysia this FridaySaravanan arrives at court, faces corruption chargesCarbon market framework to unlock RM560 million a year in climate financeU.S.-Canada trade talks collapse as Trump prepares 50% tariffs on autos and steelIran war at six months leaves Strait of Hormuz disrupted and U.S. facing strategic setbackMistrust threatens Bersatu-PH pact for Melaka pollsKennedy Center board’s Trump renaming rush questioned by US judgeUN condemns US labeling Palestine Action as extremist groupSyria’s president appoints ex-commander of Kurdish-led SDF as advisorHKEX posts record first-half profit as mainland tech listings fuel growth
AI Edge

Cyber criminals weaponise JavaScript obfuscation to hide phishing kits

JavaScript obfuscation has shifted from a software-protection gimmick to a core tactic used by phishing kits to evade detection.

Source: Cisco Talos Intelligence · August 27, 2026 at 9:01 PM · AI-assisted report

Single-source
Cyber criminals weaponise JavaScript obfuscation to hide phishing kits
Image: blog.talosintelligence.com

KUALA LUMPUR, MALAYSIA, SOUTHEAST ASIA, 28 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Share

JavaScript obfuscation has shifted from a software-protection gimmick to a core tactic used by phishing kits to evade detection.

Market Impact

According to Cisco Talos Intelligence, attackers increasingly bundle stolen credentials, fake login forms and redirection URLs into obfuscated JavaScript that is almost impossible to read without executing the code. The technique strips meaningful variable names, hides strings inside encoded arrays and pushes the actual behaviour into runtime evaluation, letting malicious scripts blend with legitimate web traffic.

Cisco Talos Intelligence notes benign uses—such as code minification or anti-tampering—still exist, but the majority of suspicious samples now centre on disguising malicious intent.

Obfuscation layers are built from a handful of well-known tricks. Strings are split into concatenated arrays, identifiers are renamed to sequences like _0x followed by hex digits, and large blocks of dead code are inserted to frustrate static analysis.

Cisco Talos Intelligence says these layers prevent simple text searches from flagging tell-tale phrases such as “https://evil.com/login.” Even when code is beautified with tools like Prettier or Biome, the original meaning rarely reappears because the identifiers and strings have already been deliberately corrupted.

The most dangerous obfuscation hides payloads that only materialise at runtime. Cisco Talos Intelligence reports that many phishing kits use eval() or Function() constructors to decode Base64, decompress gzip payloads or reassemble string tables before executing the next stage of the attack. Analysts can counter this by replacing execution sinks with logging—turning eval(payload) into console.log(payload)—and then analysing the intermediate code in isolation.

Cisco Talos Intelligence warns that attackers also weaponise the browser environment itself, inserting debugger traps, domain locks and headless-browser fingerprints to slow down or misdirect automated inspection tools.

For Malaysian businesses, the threat is immediate: phishing pages hosted on local domains or third-party sites frequented by Malaysian users can drop obfuscated JavaScript that steals corporate credentials or installs malware. Companies should isolate suspicious scripts in controlled sandboxes and use AI-assisted decoders on isolated snippets rather than feeding full payloads into external cloud services, Cisco Talos Intelligence advises.

Reporting based on Cisco Talos Intelligence. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.