Description
Decoding hardcoded hex or base64 strings and passing the results to require, eval, or Function can conceal malicious module loading or code execution. Obfuscated constants make the actual behavior harder to review. Encoding alone does not establish malicious intent; inspect the decoded contents and the purpose of executing them.
Potential impact
- Hidden loading of malicious modules or arbitrary code execution
- Malicious changes deployed because the executed code or module path is difficult to inspect
- Privilege abuse, data exposure, or additional payload downloads through concealed behavior
Remediation
- Do not interpret dynamically decoded strings as code or module paths.
- Keep required module paths readable and use static
importorrequirestatements. - If obfuscation has a legitimate purpose, document code ownership, generation, and integrity checks.
Examples
Before
javascript
const hiddenPath = Buffer.from("2e2f706c7567696e", "hex").toString();
const plugin = require(hiddenPath);
eval(atob("Y29uc29sZS5sb2coJ3J1bicp"));
After
javascript
const plugin = require("./plugin");
function runTask() {
return plugin.run();
}
Explanation:
- Before: Encoded constants are decoded at runtime and used as a module path or executable code, concealing their behavior.
- After: The module path and execution flow are explicit and can be reviewed. The omitted
./pluginimplementation must be trusted and providerun().