Ross ROSS = Recommend OSS · open-source software intelligence for agents

boku7/Loki

🧙‍♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications observed · 2026-08-28

github.com/boku7/Loki · JavaScript · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

50/100

  • Activity 74
  • Release rhythm 28
  • Longevity 36

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 32
  • age_days: 517
  • days_rel: 442
  • days_push: 159
  • n_releases_24m: 4

Full methodology

Adoption not part of the score

1360 stars · 218 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Loki is a stage-1 command and control (C2) framework written in Node.js that exploits script-jacking vulnerabilities in Electron applications. It enables red team operators to backdoor or hollow signed Electron apps without invalidating their code signing signatures, using an Azure Storage Blob C2 channel with AES-encrypted, proxy-aware communications.

Use cases

  • backdoor a signed Electron application without breaking its code signature
  • hollow an Electron app to execute arbitrary Node.js code
  • bypass Windows Defender Application Control using a trusted Electron app
  • set up a C2 channel over Azure Storage blobs for red team operations
  • run shellcode and assembly through a proxy-aware Chromium renderer process
  • evade endpoint security software by abusing trusted applications

When to choose

  • you are conducting an authorized red team engagement against Windows environments with Electron applications
  • you need to demonstrate MITRE ATT&CK T1218.015 script-jacking techniques
  • you need a teamserver-less C2 with encrypted, proxy-aware communications
  • you want to test application control and EDR evasion via signed app abuse

When to avoid

  • you need a general-purpose C2 for non-Electron implant scenarios
  • you lack authorization - this is an offensive security tool for red team use only
  • you need a mature multi-operator teamserver with extensive implant ecosystems
  • your target applications are not Electron-based

Facets

framework · maturity active

security penetration-testing cli gui security penetration-testing developer-tools windows windows cli cross-platform c2 red-team electron script-jacking post-exploitation evasion command-and-control mitre-attack nodejs

1 source

Member repositories

RepositoryRoleHealth v2
boku7/Lokimain50

For agents

markdown · JSON · MCP: product_card(name="boku7/Loki")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem