Skip to content
← LibraryTechnique entry
W-RECON-JS-SECRETSReconnaissance

Hardcoded Secrets in JS Bundles

Grep JS for API keys, AWS access keys, JWT secrets, internal hostnames — TruffleHog / SecretFinder.

§ Where this technique fits

W-RECON-JS-SECRETS is catalogued under the Reconnaissance tactic of the offensive-security kill-chain. It appears in 4 approved dossiers in the registry, typically at step 3 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Valid Accounts
    T1078 · Initial Access
    seen 2×
  2. 02
    Dependency Confusion (Public ↔ Internal)
    SUP-DEP-CONFUSION · Initial Access
    seen 1×