uses Electron ◦ Easy to analyze, just unpack ASAR file and you can see source code ◦ Source code is obfuscated tho • Second generation of malware uses Vercel pkg ◦ Hard to analyze ◦ Malware, binary itself contains various GZipped binary ◦ Static analysis is very hard • For anti-analysis and scams, JavaScript based Malware evolved like this! • I forget when it did, Novel JavaScript based Malware, BbyStealer and others banned debuggers and capture tool same time 7