Execution of hardcoded encoded data

Execution of hardcoded encoded data

Description

Decoding hardcoded hex or base64 strings and passing the results to require, eval, or Function can conceal malicious module loading or code execution. Obfuscated constants make the actual behavior harder to review. Encoding alone does not establish malicious intent; inspect the decoded contents and the purpose of executing them.

Potential impact

  • Hidden loading of malicious modules or arbitrary code execution
  • Malicious changes deployed because the executed code or module path is difficult to inspect
  • Privilege abuse, data exposure, or additional payload downloads through concealed behavior

Remediation

  • Do not interpret dynamically decoded strings as code or module paths.
  • Keep required module paths readable and use static import or require statements.
  • If obfuscation has a legitimate purpose, document code ownership, generation, and integrity checks.

Examples

Before

javascript
const hiddenPath = Buffer.from("2e2f706c7567696e", "hex").toString();
const plugin = require(hiddenPath);

eval(atob("Y29uc29sZS5sb2coJ3J1bicp"));

After

javascript
const plugin = require("./plugin");

function runTask() {
  return plugin.run();
}

Explanation:

  • Before: Encoded constants are decoded at runtime and used as a module path or executable code, concealing their behavior.
  • After: The module path and execution flow are explicit and can be reviewed. The omitted ./plugin implementation must be trusted and provide run().

References