# T1059.007 JavaScript

> As of 2026-10-05, T1059.007 (JavaScript) appears in 241 tracked threats, first reported 2025-10-13 and most recently 2026-10-04, with linked actors including TeamPCP, Contagious Interview, APT38; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 241 (73 critical, 148 high, 17 medium, 2 low)
- **First seen:** 2025-10-13
- **Last seen:** 2026-10-04
- **Threat actors:** 65
- **Detection rules:** 773 (counts only; Blue tier and above)

## Key facts

- **ID:** T1059.007
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Parent:** T1059
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1059/007/

## Activity timeline

T1059.007 first appeared in tracked threats on 2025-10-13 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 58 reports, and 240 of the 241 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1059.007 JavaScript is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059). Threadlinqs maps 241 of 2623 tracked threats (9.2%) to it; by severity that is 73 critical, 148 high, 17 medium, 2 low.

Threats that use T1059.007 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (165 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (151 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (123 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (120 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (109 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

65 tracked threat actors appear in the threats that use T1059.007; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (19), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (9), [APT38](https://intel.threadlinqs.com/actor/APT38) (7), [WageMole](https://intel.threadlinqs.com/actor/WageMole) (7), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (6).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1059.007.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1059.007, per MITRE ATT&CK.

- Command — Command Execution
- Module — Module Load
- Process — Process Creation
- Script — Script Execution

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 19
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 9
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 7
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 7
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 6
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 6
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 6
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 5
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 4
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 4
- [UNC5342](https://intel.threadlinqs.com/actor/UNC5342) — 4
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 3

## Tracked threats

The 30 most recent of 241 tracked threats that use T1059.007.

- [Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697) Enable Root Code…](https://intel.threadlinqs.com/threat/TL-2026-2912) — critical — 2026-10-04
- [Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features…](https://intel.threadlinqs.com/threat/TL-2026-2894) — critical — 2026-10-04
- [AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…](https://intel.threadlinqs.com/threat/TL-2026-2880) — high — 2026-10-03
- [Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to…](https://intel.threadlinqs.com/threat/TL-2026-2865) — critical — 2026-10-03
- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on…](https://intel.threadlinqs.com/threat/TL-2026-2841) — medium — 2026-10-02
- [Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-2806) — high — 2026-09-30
- [Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)](https://intel.threadlinqs.com/threat/TL-2026-2803) — critical — 2026-09-30
- [MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer](https://intel.threadlinqs.com/threat/TL-2026-2801) — high — 2026-09-30
- [PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled…](https://intel.threadlinqs.com/threat/TL-2026-2785) — medium — 2026-09-29
- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — high — 2026-09-29
- [ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…](https://intel.threadlinqs.com/threat/TL-2026-2730) — high — 2026-09-28
- [Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)](https://intel.threadlinqs.com/threat/TL-2026-2717) — high — 2026-09-27
- [PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistence](https://intel.threadlinqs.com/threat/TL-2026-2674) — high — 2026-09-26
- [Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-2665) — high — 2026-09-26
- [Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…](https://intel.threadlinqs.com/threat/TL-2026-2661) — high — 2026-09-26
- [Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)](https://intel.threadlinqs.com/threat/TL-2026-2657) — high — 2026-09-26
- [Adform Ad-Tech Platform Compromised: Trojanized Tracking Script Serves Crypto Clipboard Stealer via…](https://intel.threadlinqs.com/threat/TL-2026-2656) — high — 2026-09-26
- [Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2670) — high — 2026-09-25
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac users](https://intel.threadlinqs.com/threat/TL-2026-2651) — high — 2026-09-25
- [Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin…](https://intel.threadlinqs.com/threat/TL-2026-2648) — high — 2026-09-25
- [MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor module](https://intel.threadlinqs.com/threat/TL-2026-2641) — high — 2026-09-24
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…](https://intel.threadlinqs.com/threat/TL-2026-2635) — high — 2026-09-23
- [Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…](https://intel.threadlinqs.com/threat/TL-2026-2633) — critical — 2026-09-23
- [Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systems](https://intel.threadlinqs.com/threat/TL-2026-2612) — medium — 2026-09-22
- [BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection](https://intel.threadlinqs.com/threat/TL-2026-2610) — medium — 2026-09-21
- [GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcp](https://intel.threadlinqs.com/threat/TL-2026-2605) — high — 2026-09-21
- [Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Install](https://intel.threadlinqs.com/threat/TL-2026-2597) — critical — 2026-09-21

## Related CVEs

CVEs referenced by the tracked threats that use T1059.007, most frequent first.

- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2024-42009](https://intel.threadlinqs.com/cve/CVE-2024-42009)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2020-16040](https://intel.threadlinqs.com/cve/CVE-2020-16040)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-38003](https://intel.threadlinqs.com/cve/CVE-2021-38003)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2022-48503](https://intel.threadlinqs.com/cve/CVE-2022-48503)
- [CVE-2023-32409](https://intel.threadlinqs.com/cve/CVE-2023-32409)
- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434)
- [CVE-2023-36025](https://intel.threadlinqs.com/cve/CVE-2023-36025)
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606)
- [CVE-2023-43000](https://intel.threadlinqs.com/cve/CVE-2023-43000)
- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770)
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-14174](https://intel.threadlinqs.com/cve/CVE-2025-14174)
- [CVE-2025-25249](https://intel.threadlinqs.com/cve/CVE-2025-25249)
- [CVE-2025-27915](https://intel.threadlinqs.com/cve/CVE-2025-27915)
- [CVE-2025-31277](https://intel.threadlinqs.com/cve/CVE-2025-31277)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)

## Detection coverage

Threadlinqs maintains 773 detection rules mapped to T1059.007 (SPL 283, KQL 239, Sigma 249, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

773 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) — 1050 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1059.007
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
