# boku7/Loki

🧙‍♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

Repository: https://github.com/boku7/Loki
Canonical: https://ross.abutalabs.com/products/boku7-loki
Language: JavaScript
License: NOASSERTION
License Family: other
Last push: 2026-03-27T20:09:53+00:00

## Health v2 (maintenance only)
Score: 50/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 74, release rhythm 28, longevity 36
- inputs: {"age_days": 517, "days_push": 159, "days_rel": 442, "gap_med": 32, "n_releases_24m": 4}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1360, forks 218 (observed 2026-08-28T04:04:29.847475+00:00)

## What it is
Loki is a stage-1 command and control (C2) framework written in Node.js that exploits script-jacking vulnerabilities in Electron applications. It enables red team operators to backdoor or hollow signed Electron apps without invalidating their code signing signatures, using an Azure Storage Blob C2 channel with AES-encrypted, proxy-aware communications.

## Use cases
- backdoor a signed Electron application without breaking its code signature
- hollow an Electron app to execute arbitrary Node.js code
- bypass Windows Defender Application Control using a trusted Electron app
- set up a C2 channel over Azure Storage blobs for red team operations
- run shellcode and assembly through a proxy-aware Chromium renderer process
- evade endpoint security software by abusing trusted applications

## When to choose
- you are conducting an authorized red team engagement against Windows environments with Electron applications
- you need to demonstrate MITRE ATT&CK T1218.015 script-jacking techniques
- you need a teamserver-less C2 with encrypted, proxy-aware communications
- you want to test application control and EDR evasion via signed app abuse

## When to avoid
- you need a general-purpose C2 for non-Electron implant scenarios
- you lack authorization - this is an offensive security tool for red team use only
- you need a mature multi-operator teamserver with extensive implant ecosystems
- your target applications are not Electron-based

## Facets
- artifact type: framework
- maturity: active
- function: security, penetration-testing, cli, gui
- domain: security, penetration-testing, developer-tools, windows
- platform: windows, cli, cross-platform
- tags: c2, red-team, electron, script-jacking, post-exploitation, evasion, command-and-control, mitre-attack, nodejs

## Member repositories
- boku7/Loki (main) score 50

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:29.847475+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:41:38.343876+00:00, confidence not recorded.
  - readme: https://github.com/boku7/Loki (fetched 2026-08-28T04:04:29.847475+00:00, sha 69b5b627b4e5)
- Data as of 2026-08-30T08:39:29.467469+00:00.
