Obfuscated Phishing and Exfiltration in Node Environments
An adversary has deployed an obfuscated phishing kit on an asset with developer tools like npm, using encoded HTTP query parameters to exfiltrate stolen credentials and session cookies to rare or known-malicious domains.
Based on research by Cisco Talos 2026-09-29 9 steps · 3 queries T1041 T1115 T1176 T1566
Brief
Why this hunt
Cisco Talos recently detailed how phishing kits use JavaScript obfuscation to hide malicious logic from static analysis in their article, JavaScript obfuscation: From party trick to phishing kit. While many detections focus on the initial delivery, this hunt looks for the aftermath: the successful exfiltration of stolen data from developer environments where these kits are often executed via malicious packages or local testing.
How the Hunt Flows
The first phase scopes the environment to identify high-risk assets. The query searches software inventory for any host running the npm package manager or related developer tooling. Narrowing the focus to developer machines filters out noise from general administrative or guest traffic and targets a population where high-entropy network traffic is common but requires scrutiny.
The second phase runs two concurrent checks on the scoped hosts to find evidence of data movement. The HTTP logic looks for unusually long query strings or signatures of Base64 padding (such as "==" or "d=") in URLs. Simultaneously, the DNS logic identifies resolutions for known phishing infrastructure or domains with very low prevalence across the estate.
In the final phase, an automated agent correlates these findings. It evaluates whether the hosts triggering encoded HTTP alerts are the same ones contacting rare or suspicious domains. This pivot transforms isolated events into a cohesive attack chain, allowing the agent to provide a per-host verdict of malicious, suspicious, or benign before a responder takes action.
Blind Spots
This hunt focuses on URI-based exfiltration. If an adversary sends credentials within the encrypted body of a POST request, this telemetry does not see the sensitive data. Additionally, static indicator lists for DNS will miss newly registered domains or domain generation algorithms (DGAs). The hunt relies on the rarity of a domain to flag potential new infrastructure.
Running the Hunt
This design is available as an open hunt.md playbook. You can import it directly into Huntbase or any compatible runtime that supports the hunt.md format. The playbook includes the SQLite queries and the automated triage logic needed to process the results across your software inventory, network, and endpoint logs.
In this series
Steps
-
Find hosts with npm installed
Query · scopingIdentify the subset of the estate with development tools installed, as these are the primary targets for this scenario.
reads hb_software_inventorysqlSELECT DISTINCT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) = 'npm' OR LOWER(package_type) = 'npm')What a hit looks like. A list of hosts that have npm installed. No rows means no npm installations are visible in software inventory.
-
HTTP exfiltration via encoded parameters
Query · detection candidateIdentify HTTP requests containing high-entropy or Base64-encoded query parameters typical of exfiltration scripts on developer assets.
reads hb_http_activitysqlSELECT device_hostname, url_hostname, url_path, url_query, user_agent, time FROM hb_http_activity WHERE (LENGTH(url_query) > 60 OR url_query LIKE '%==%' OR url_query LIKE '%d=%' OR url_query LIKE '%p=%' OR url_query LIKE '%token%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)What a hit looks like. Requests showing sensitive or encoded data in the URL. Benign hits include development testing; exfiltration typically hits rare or non-corporate domains.
-
DNS lookups for rare or known phishing infrastructure
Query · baselineIdentify resolutions for known malicious domains or rare domains resolved by only a few hosts within the scoped developer population.
reads hb_dns_activitysqlSELECT query_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_dns_activity WHERE (instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY query_hostname HAVING host_count <= 2What a hit looks like. DNS resolutions of intelligence-listed domains or rare domains. Rare domains on developer assets may indicate new phishing proxies.
-
Evaluate delivery and exfiltration evidence
Agent triageAnalyze the combined HTTP patterns and DNS hits to determine if they represent a cohesive attack chain.
-
Route based on verdict
DecisionDirect the response based on the agent's findings.
-
Isolate affected host
Response actionContain the threat by isolating the host suspected of exfiltrating credentials.
-
Analyst manual review
Analyst taskVerify the agent's findings and review any undecipherable or suspicious telemetry.
-
Hunt close-out
Analyst taskDocument findings and archive the hunt results.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Phishing Kit and Social Engineering Delivery T1566 |
Yes | detect-rare-dns |
| Exfiltration via Web Request T1041 |
Yes | detect-encoded-http |
| Malicious Package Installation T1566 |
Out of scope | Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series. |
| JavaScript Obfuscation and Anti-Analysis T1176 |
Out of scope | Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series. |
| Browser Extension Abuse T1176 |
Out of scope | Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series. |
| Credential and Browser Data Collection T1115 |
Out of scope | Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series. |
Blind spots
- Needs hb_http_activity with decrypted payloads or endpoint browser instrumentation. The hunt only sees parameters in the URL; exfiltration hidden in an encrypted POST body remains invisible. It would answer whether credentials were sent in the request body of a POST request.
- Needs real-time threat intelligence feed for newly registered domains. Static indicator lists will miss phishing infrastructure that rotates daily. It would answer whether a previously unknown domain is a phishing proxy.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of telemetry history to examine. |
phishing_domains | list[domain] | example.com, phish-kit.live, auth-verify.net | Known phishing or exfiltration domains from threat intelligence. |
scope_hosts | list[host] | — | Limit the hunt to specific hosts; leave empty to query all hosts with npm installed. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Web server / proxy logs | siem | network |
Source
---
analysis: A simple rule for 'password' in a URL generates many false positives. This
hunt combines encoded parameter patterns with developer-host scoping and a stack-count
on DNS destinations to isolate the rare exfiltration signal from normal web development
traffic.
blind_spots:
- id: no-http-decryption
question: whether credentials were sent in the request body of a POST request
requires: hb_http_activity with decrypted payloads or endpoint browser instrumentation
risk: The hunt only sees parameters in the URL; exfiltration hidden in an encrypted
POST body remains invisible.
stage: exfiltration-over-c2
- id: ephemeral-domains
question: whether a previously unknown domain is a phishing proxy
requires: real-time threat intelligence feed for newly registered domains
risk: Static indicator lists will miss phishing infrastructure that rotates daily.
stage: initial-access-phishing-delivery
coverage:
- stage: initial-access-phishing-delivery
status: covered
steps:
- detect-rare-dns
- stage: exfiltration-over-c2
status: covered
steps:
- detect-encoded-http
- reason: 'Belongs to another part of the ''JavaScript obfuscation: From party trick
to phishing kit'' series.'
stage: execution-npm-install-scripts
status: out_of_scope
- reason: 'Belongs to another part of the ''JavaScript obfuscation: From party trick
to phishing kit'' series.'
stage: defense-evasion-script-obfuscation
status: out_of_scope
- reason: 'Belongs to another part of the ''JavaScript obfuscation: From party trick
to phishing kit'' series.'
stage: persistence-browser-extensions
status: out_of_scope
- reason: 'Belongs to another part of the ''JavaScript obfuscation: From party trick
to phishing kit'' series.'
stage: collection-credential-and-cookie-theft
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: Phishing kits use obfuscation to bypass static email and web filters.
Detecting successful exfiltration via behavioral patterns like high-entropy URL
parameters on developer assets is critical for containing active intrusions.
methodology: model-assisted
trigger: intel-report
hypothesis: An adversary has deployed an obfuscated phishing kit on an asset with
developer tools like npm, using encoded HTTP query parameters to exfiltrate stolen
credentials and session cookies to rare or known-malicious domains.
labels:
- hunt
- attack.t1566
- attack.t1041
- attack.t1115
- attack.t1176
- collection
- defense evasion
- execution
- exfiltration
- initial access
- persistence
name: Obfuscated Phishing and Exfiltration in Node Environments
parameters:
lookback_days:
default: '14'
description: Days of telemetry history to examine.
from:
kind: manual
observed: '2024-05-22'
ref: standard-retention
type: number
phishing_domains:
default:
- example.com
- phish-kit.live
- auth-verify.net
description: Known phishing or exfiltration domains from threat intelligence.
from:
kind: article
observed: '2026-08-27'
ref: https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/
type: list[domain]
scope_hosts:
default: []
description: Limit the hunt to specific hosts; leave empty to query all hosts
with npm installed.
from:
kind: manual
observed: '2024-05-22'
ref: analyst-defined
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: The hunt first identifies hosts with npm installed. Narrowing to these
developer-focused assets reduces noise from general web browsing and focuses on
a high-risk group where obfuscated scripts are frequently observed during installation
or development.
references:
- name: 'JavaScript obfuscation: From party trick to phishing kit'
url: https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/
related:
- hunt: npm-malicious-install-scripts
reason: This hunt focuses on the network exfiltration of phishing kits; malicious
install scripts are a separate stage involving process and file telemetry.
relation: out-of-scope-alternative
- hunt: obfuscated-js-and-local-collection
relation: follows
scenario:
stages:
- name: Phishing Kit and Social Engineering Delivery
observables:
- phishing kit
- fake CAPTCHA
- fake update flows
- compromised website injections
slug: initial-access-phishing-delivery
tactic: initial-access
techniques:
- T1566
- name: Malicious Package Installation
observables:
- npm package install scripts
- npm tokens
slug: execution-npm-install-scripts
tactic: execution
techniques:
- T1566
- name: JavaScript Obfuscation and Anti-Analysis
observables:
- eval()
- atob()
- String.fromCharCode()
- atob('ZXZhbA==')
- JSFuck
- navigator.webdriver
- control-flow flattening
- _0x identifiers
slug: defense-evasion-script-obfuscation
tactic: defense-evasion
techniques:
- T1176
- name: Browser Extension Abuse
observables:
- browser extension abuse
- malicious software extensions
slug: persistence-browser-extensions
tactic: persistence
techniques:
- T1176
- name: Credential and Browser Data Collection
observables:
- window.document.cookie
- clipboard contents
- clip.exe
- pbpaste
slug: collection-credential-and-cookie-theft
tactic: collection
techniques:
- T1115
- name: Exfiltration via Web Request
observables:
- https://example.com
- fetch
- ?password=
slug: exfiltration-over-c2
tactic: exfiltration
techniques:
- T1041
summary: Threat actors employ sophisticated JavaScript obfuscation techniques, including
packing, encoding, and JSFuck, to conceal malicious payloads in phishing kits,
malware loaders, and npm packages. These scripts often include anti-analysis features
like browser fingerprinting and control-flow flattening to evade detection while
exfiltrating credentials and cookies from victim systems.
series:
index: 2
slug: javascript-obfuscation-from-party-trick-to-phishing-kit
title: 'JavaScript obfuscation: From party trick to phishing kit'
total: 2
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
web:
category: siem
name: Web server / proxy logs
telemetry:
- network
tlp: clear
type: investigation
---
# Obfuscated Phishing and Exfiltration in Node Environments
This hunt targets the delivery and exfiltration stages of a phishing attack. It specifically scopes to hosts running the npm package manager, where malicious install scripts or dev-tooling compromises are more likely. The hunt searches for application-layer indicators of exfiltration, such as high-entropy query strings or Base64 padding in URLs, and corroborates these with rare DNS resolutions to known phishing infrastructure. An agent evaluates the combined evidence to distinguish benign dev traffic from active credential theft.
## scope-npm-hosts
<!-- Find hosts with npm installed -->
Identify the subset of the estate with development tools installed, as these are the primary targets for this scenario.
```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hosts that have npm installed. No rows means no npm installations
are visible in software inventory.
reads:
- device_hostname
- package_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT DISTINCT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) = 'npm' OR LOWER(package_type) = 'npm')
```
## parallel-corroboration
<!-- Corroborate HTTP and DNS telemetry -->
parallel:
- → detect-encoded-http
- → detect-rare-dns
join: → triage-agent
## detect-encoded-http
<!-- HTTP exfiltration via encoded parameters -->
Identify HTTP requests containing high-entropy or Base64-encoded query parameters typical of exfiltration scripts on developer assets.
```sqlite target=web role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Requests showing sensitive or encoded data in the URL. Benign hits include
development testing; exfiltration typically hits rare or non-corporate domains.
reads:
- device_hostname
- url_hostname
- url_path
- url_query
- user_agent
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, url_hostname, url_path, url_query, user_agent, time FROM hb_http_activity WHERE (LENGTH(url_query) > 60 OR url_query LIKE '%==%' OR url_query LIKE '%d=%' OR url_query LIKE '%p=%' OR url_query LIKE '%token%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```
## detect-rare-dns
<!-- DNS lookups for rare or known phishing infrastructure -->
Identify resolutions for known malicious domains or rare domains resolved by only a few hosts within the scoped developer population.
```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, phishing_domains=phishing_domains, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: DNS resolutions of intelligence-listed domains or rare domains. Rare domains
on developer assets may indicate new phishing proxies.
prevalence:
by: device_hostname
key:
- query_hostname
rare_below: 3
reads:
- query_hostname
- device_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT query_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_dns_activity WHERE (instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY query_hostname HAVING host_count <= 2
```
## triage-agent
<!-- Evaluate delivery and exfiltration evidence -->
```agent target=hunter
cite: required
context:
- scope-npm-hosts
- detect-encoded-http
- detect-rare-dns
max_iterations: 4
objective: Determine if the observed high-entropy HTTP parameters and rare DNS lookups
indicate a successful phishing attack and data exfiltration from hosts with npm
installed.
success_criteria: A per-host verdict citing specific HTTP requests and DNS resolutions.
tools:
- endpoint
- web
```
## route-decision
<!-- Route based on verdict -->
if~: "the triage-agent verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: no-http-decryption)
else: → close-out
## isolate-host
<!-- Isolate affected host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host and initiate a credential reset for the users identified in the HTTP logs.
```
→ analyst-review
## analyst-review
<!-- Analyst manual review -->
```manual target=analyst
Review the full URL patterns and DNS results. Check if the destination domains have been recently registered or are associated with known phishing kits. Attempt to decode Base64 parameters to confirm credential theft.
```
→ close-out
## close-out
<!-- Hunt close-out -->
```manual target=analyst
Record the exfiltration domains and user accounts involved. Provide tuning suggestions for the detection candidate if necessary.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.