{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Phishing kits use obfuscation to bypass static email and web filters. Detecting successful exfiltration via behavioral patterns like high-entropy URL parameters on developer assets is critical for containing active intrusions."
      },
      "name": "Obfuscated Phishing and Exfiltration in Node Environments",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1041",
        "attack.t1115",
        "attack.t1176",
        "collection",
        "defense evasion",
        "execution",
        "exfiltration",
        "initial access",
        "persistence"
      ],
      "series": {
        "slug": "javascript-obfuscation-from-party-trick-to-phishing-kit",
        "index": 2,
        "title": "JavaScript obfuscation: From party trick to phishing kit",
        "total": 2
      },
      "related": [
        {
          "hunt": "npm-malicious-install-scripts",
          "reason": "This hunt focuses on the network exfiltration of phishing kits; malicious install scripts are a separate stage involving process and file telemetry.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "obfuscated-js-and-local-collection",
          "relation": "follows"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple rule for 'password' in a URL generates many false positives. This hunt combines encoded parameter patterns with developer-host scoping and a stack-count on DNS destinations to isolate the rare exfiltration signal from normal web development traffic.",
      "coverage": [
        {
          "stage": "initial-access-phishing-delivery",
          "steps": [
            "detect-rare-dns"
          ],
          "status": "covered"
        },
        {
          "stage": "exfiltration-over-c2",
          "steps": [
            "detect-encoded-http"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-npm-install-scripts",
          "reason": "Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "defense-evasion-script-obfuscation",
          "reason": "Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-browser-extensions",
          "reason": "Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "collection-credential-and-cookie-theft",
          "reason": "Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Phishing Kit and Social Engineering Delivery",
            "slug": "initial-access-phishing-delivery",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "phishing kit",
              "fake CAPTCHA",
              "fake update flows",
              "compromised website injections"
            ]
          },
          {
            "name": "Malicious Package Installation",
            "slug": "execution-npm-install-scripts",
            "tactic": "execution",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "npm package install scripts",
              "npm tokens"
            ]
          },
          {
            "name": "JavaScript Obfuscation and Anti-Analysis",
            "slug": "defense-evasion-script-obfuscation",
            "tactic": "defense-evasion",
            "techniques": [
              "T1176"
            ],
            "observables": [
              "eval()",
              "atob()",
              "String.fromCharCode()",
              "atob('ZXZhbA==')",
              "JSFuck",
              "navigator.webdriver",
              "control-flow flattening",
              "_0x identifiers"
            ]
          },
          {
            "name": "Browser Extension Abuse",
            "slug": "persistence-browser-extensions",
            "tactic": "persistence",
            "techniques": [
              "T1176"
            ],
            "observables": [
              "browser extension abuse",
              "malicious software extensions"
            ]
          },
          {
            "name": "Credential and Browser Data Collection",
            "slug": "collection-credential-and-cookie-theft",
            "tactic": "collection",
            "techniques": [
              "T1115"
            ],
            "observables": [
              "window.document.cookie",
              "clipboard contents",
              "clip.exe",
              "pbpaste"
            ]
          },
          {
            "name": "Exfiltration via Web Request",
            "slug": "exfiltration-over-c2",
            "tactic": "exfiltration",
            "techniques": [
              "T1041"
            ],
            "observables": [
              "https://example.com",
              "fetch",
              "?password="
            ]
          }
        ],
        "summary": "Threat actors employ sophisticated JavaScript obfuscation techniques, including packing, encoding, and JSFuck, to conceal malicious payloads in phishing kits, malware loaders, and npm packages. These scripts often include anti-analysis features like browser fingerprinting and control-flow flattening to evade detection while exfiltrating credentials and cookies from victim systems."
      },
      "severity": "high",
      "rationale": "The hunt first identifies hosts with npm installed. Narrowing to these developer-focused assets reduces noise from general web browsing and focuses on a high-risk group where obfuscated scripts are frequently observed during installation or development.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has deployed an obfuscated phishing kit on an asset with developer tools like npm, using encoded HTTP query parameters to exfiltrate stolen credentials and session cookies to rare or known-malicious domains.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-defined",
            "kind": "manual",
            "observed": "2024-05-22"
          },
          "type": "list[host]",
          "default": [],
          "description": "Limit the hunt to specific hosts; leave empty to query all hosts with npm installed."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-retention",
            "kind": "manual",
            "observed": "2024-05-22"
          },
          "type": "number",
          "default": "14",
          "description": "Days of telemetry history to examine."
        },
        "phishing_domains": {
          "from": {
            "ref": "https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/",
            "kind": "article",
            "observed": "2026-08-27"
          },
          "type": "list[domain]",
          "default": [
            "example.com",
            "phish-kit.live",
            "auth-verify.net"
          ],
          "description": "Known phishing or exfiltration domains from threat intelligence."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/",
          "name": "JavaScript obfuscation: From party trick to phishing kit"
        }
      ],
      "blind_spots": [
        {
          "id": "no-http-decryption",
          "risk": "The hunt only sees parameters in the URL; exfiltration hidden in an encrypted POST body remains invisible.",
          "stage": "exfiltration-over-c2",
          "question": "whether credentials were sent in the request body of a POST request",
          "requires": "hb_http_activity with decrypted payloads or endpoint browser instrumentation"
        },
        {
          "id": "ephemeral-domains",
          "risk": "Static indicator lists will miss phishing infrastructure that rotates daily.",
          "stage": "initial-access-phishing-delivery",
          "question": "whether a previously unknown domain is a phishing proxy",
          "requires": "real-time threat intelligence feed for newly registered domains"
        }
      ]
    },
    "name": "Obfuscated Phishing and Exfiltration in Node Environments",
    "description": "This hunt targets the delivery and exfiltration stages of a phishing attack. It specifically scopes to hosts running the npm package manager, where malicious install scripts or dev-tooling compromises are more likely. The hunt searches for application-layer indicators of exfiltration, such as high-entropy query strings or Base64 padding in URLs, and corroborates these with rare DNS resolutions to known phishing infrastructure. An agent evaluates the combined evidence to distinguish benign dev traffic from active credential theft."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "javascript-obfuscation-from-party-trick-to-phishing-kit",
          "index": 2,
          "title": "JavaScript obfuscation: From party trick to phishing kit",
          "total": 2
        },
        "coverage": [
          {
            "stage": "initial-access-phishing-delivery",
            "steps": [
              "detect-rare-dns"
            ],
            "status": "covered"
          },
          {
            "stage": "exfiltration-over-c2",
            "steps": [
              "detect-encoded-http"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-npm-install-scripts",
            "reason": "Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "defense-evasion-script-obfuscation",
            "reason": "Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-browser-extensions",
            "reason": "Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "collection-credential-and-cookie-theft",
            "reason": "Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary has deployed an obfuscated phishing kit on an asset with developer tools like npm, using encoded HTTP query parameters to exfiltrate stolen credentials and session cookies to rare or known-malicious domains.",
        "blind_spots": [
          {
            "id": "no-http-decryption",
            "risk": "The hunt only sees parameters in the URL; exfiltration hidden in an encrypted POST body remains invisible.",
            "stage": "exfiltration-over-c2",
            "question": "whether credentials were sent in the request body of a POST request",
            "requires": "hb_http_activity with decrypted payloads or endpoint browser instrumentation"
          },
          {
            "id": "ephemeral-domains",
            "risk": "Static indicator lists will miss phishing infrastructure that rotates daily.",
            "stage": "initial-access-phishing-delivery",
            "question": "whether a previously unknown domain is a phishing proxy",
            "requires": "real-time threat intelligence feed for newly registered domains"
          }
        ],
        "scoping_notes": "The hunt first identifies hosts with npm installed. Narrowing to these developer-focused assets reduces noise from general web browsing and focuses on a high-risk group where obfuscated scripts are frequently observed during installation or development.",
        "beyond_detection": "A simple rule for 'password' in a URL generates many false positives. This hunt combines encoded parameter patterns with developer-host scoping and a stack-count on DNS destinations to isolate the rare exfiltration signal from normal web development traffic."
      }
    },
    {
      "id": "scope-npm-hosts",
      "type": "query",
      "label": "Find hosts with npm installed",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) = 'npm' OR LOWER(package_type) = 'npm')",
        "surface": "hb_software_inventory",
        "description": "Identify the subset of the estate with development tools installed, as these are the primary targets for this scenario.",
        "expected_signal": "A list of hosts that have npm installed. No rows means no npm installations are visible in software inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Find hosts with npm installed",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) = 'npm' OR LOWER(package_type) = 'npm')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts that have npm installed. No rows means no npm installations are visible in software inventory.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "detect-encoded-http",
      "type": "query",
      "label": "HTTP exfiltration via encoded parameters",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, url_query, user_agent, time FROM hb_http_activity WHERE (LENGTH(url_query) > 60 OR url_query LIKE '%==%' OR url_query LIKE '%d=%' OR url_query LIKE '%p=%' OR url_query LIKE '%token%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "surface": "hb_http_activity",
        "description": "Identify HTTP requests containing high-entropy or Base64-encoded query parameters typical of exfiltration scripts on developer assets.",
        "expected_signal": "Requests showing sensitive or encoded data in the URL. Benign hits include development testing; exfiltration typically hits rare or non-corporate domains."
      },
      "parents": [
        {
          "id": "scope-npm-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "HTTP exfiltration via encoded parameters",
        "reads": [
          "device_hostname",
          "url_hostname",
          "url_path",
          "url_query",
          "user_agent",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, url_query, user_agent, time FROM hb_http_activity WHERE (LENGTH(url_query) > 60 OR url_query LIKE '%==%' OR url_query LIKE '%d=%' OR url_query LIKE '%p=%' OR url_query LIKE '%token%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "silence": "not_evidence_of_absence",
        "expected": "Requests showing sensitive or encoded data in the URL. Benign hits include development testing; exfiltration typically hits rare or non-corporate domains.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "detect-rare-dns",
      "type": "query",
      "label": "DNS lookups for rare or known phishing infrastructure",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT query_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_dns_activity WHERE (instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY query_hostname HAVING host_count <= 2",
        "surface": "hb_dns_activity",
        "description": "Identify resolutions for known malicious domains or rare domains resolved by only a few hosts within the scoped developer population.",
        "expected_signal": "DNS resolutions of intelligence-listed domains or rare domains. Rare domains on developer assets may indicate new phishing proxies."
      },
      "parents": [
        {
          "id": "scope-npm-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "DNS lookups for rare or known phishing infrastructure",
        "reads": [
          "query_hostname",
          "device_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT query_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_dns_activity WHERE (instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY query_hostname HAVING host_count <= 2",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "DNS resolutions of intelligence-listed domains or rare domains. Rare domains on developer assets may indicate new phishing proxies.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "query_hostname"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-agent",
      "type": "analytic",
      "label": "Evaluate delivery and exfiltration evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "scope-npm-hosts",
          "detect-encoded-http",
          "detect-rare-dns"
        ],
        "objective": "Determine if the observed high-entropy HTTP parameters and rare DNS lookups indicate a successful phishing attack and data exfiltration from hosts with npm installed.",
        "description": "Analyze the combined HTTP patterns and DNS hits to determine if they represent a cohesive attack chain.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict of malicious, suspicious, or benign based on the telemetry overlap.",
        "success_criteria": "A per-host verdict citing specific HTTP requests and DNS resolutions."
      },
      "parents": [
        {
          "id": "detect-encoded-http",
          "kind": "merge"
        },
        {
          "id": "detect-rare-dns",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-decision",
      "type": "checkpoint",
      "label": "Route based on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-agent verdict is malicious for at least one host",
        "condition": "the triage-agent verdict is malicious for at least one host",
        "blind_spot": "no-http-decryption",
        "confidence": "high",
        "description": "Direct the response based on the agent's findings.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-agent"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate affected host",
      "config": {
        "target": "endpoint",
        "description": "Contain the threat by isolating the host suspected of exfiltrating credentials.",
        "instructions": "Isolate the host and initiate a credential reset for the users identified in the HTTP logs.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst manual review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's findings and review any undecipherable or suspicious telemetry.",
        "instructions": "Review the full URL patterns and DNS results. Check if the destination domains have been recently registered or are associated with known phishing kits. Attempt to decode Base64 parameters to confirm credential theft."
      },
      "parents": [
        {
          "id": "route-decision",
          "branch": "default"
        },
        {
          "id": "route-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt close-out",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and archive the hunt results.",
        "instructions": "Record the exfiltration domains and user accounts involved. Provide tuning suggestions for the detection candidate if necessary."
      },
      "parents": [
        {
          "id": "route-decision",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}