Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Loki — 🧙‍♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications | Kitploit
Tools/GitHubGitHub/boku7/loki
Persistence MechanismsExploitationIDS/IPS EvasionShellcodePost-ExploitationCommand and ControlRed TeamingPayload Development
GitHubboku7/loki

Loki

🧙‍♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

View Repository
1.4k220206 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🧙‍♂️ Loki Command & Control

Loki is a stage-1 command and control (C2) framework written in Node.js, built to script-jack vulnerable Electron apps MITRE ATT&CK T1218.015. Developed for red team operations, Loki enables evasion of security software and bypasses application controls by exploiting trusted, signed Electron apps.

Script-jacking hijacks the execution flow of an Electron app by modifying JavaScript files loaded in at runtime with arbitrary Node.js code. This technique can be leveraged to:

  • Backdoor Electron app
  • Hollow Electron app
  • Chain execution to another process

While several tools already address leveraging script-jacking to chain execution to another process, Loki is the first to enable backdooring and hollowing of signed Electron apps without invalidating their code signing signature.

For more details on how Loki works, checkout this blog post:

  • Bypassing Windows Defender Application Control with Loki C2

🚀 Contributors

NameContributions
Bobby CookeCreator & Maintainer
Dylan TranCreator
Ellis SpringeAlpha Tester
Shawn JonesAssembly Execution Code
Trusted SecCOFFLoader Code
Simon ExleyVideo Creator
Clinton ElvesVideo Creator
John HammondVideo Creator

Videos

Check out this video by John Hammond on backdooring Cursor AI with Loki C2! 🎩

  • In the video he walks through discovering a new vulnerable Electron application, backdooring it with Loki C2, getting setup with the client GUI, and we even came up with two ways to keep the app running persistently in the background 🪄 -- Cursor runs normally from the end users perspective! 🥷

I Backdoored Cursor AI

Check out this video by Simon Exley & Clinton Elves on getting up and running with Loki C2! 🧙‍♂️

Bypassing Windows Defender Application Control with Loki C2

Features & Details

  • Azure Storage Blob C2 channel
    • SAS Token to protect C2 storage account
  • AES encrypted C2 messages
  • Proxy-aware agent
    • Uses Chromium renderer child processes for agent, shellcode execution, and assembly fork-n-run style execution -- inherits proxy-aware capabilities of Chromium.
  • Teamserver-less
    • Unlike traditional C2's where agents send messages to a Teamserver, there is no Teamserver
    • The GUI client & agents both checkin to the same data-store
  • Hidden exection -- runs in the background

Commands

All agent commands are written in native Node.JS and do not require additional dependencies or library load events. With the exception of the scexec and assembly commands which do a library load on keytar.node and assembly.node

  • All commands accept paths using /, \ in paths will not work.
CommandDescription
helpDisplay help. Usage: help or help scan
pwdPrint working directory
lsFile and directory listing
catDisplay contents of a file
envDisplay process environment variables
spawnSpawn a child process
drivesList drives
mvMove a file to a new destination
sleepSleep for seconds with jitter
cpCopy a source file to a destination
exit-allExits the agent, agent won't callback anymore
loadLoad a node PE file from disk into the process
scexecExecute shellcode
assemblyExecute a .NET assembly and get command output
uploadUpload a file from your local operator box to the remote agent box
downloadDownload a file from remote agent box to local operator box
scanPerform TCP network scan across CIDR range with selected ports
dnsDNS lookup. Leverages systems DNS configuration
setSet the Node load paths for assembly node and scexec nodes
bofExecute a COFF file and return output

Set - Loading Nodes from Application Control Exclusion Paths

  • If there are application control rules preventing library loads for the node files you can use the set command to change the load paths for assembly.node and scexec.node.
  • By using ls, cat, cp and mv you may be able to enumerate the application control rules to discover a writable directory that is an exclusion.
  • With this you can put the node files in the exclusion directory and use the set command to change their load path to the exclusion directory to bypass the application control.
  • For more details on this attack vector see the CRTO2 course by Daniel Duggan (@_RastaMouse)
[04-04-2025 8:50AM MST] advsim$ help set
Set the Node load paths for assembly node and scexec nodes
	set scexec_path C:/Users/user/AppData/ExcludedApp/scexec.node
	set assembly_path C:/Users/user/AppData/ExcludedApp/assembly.node
[04-04-2025 8:51AM MST] advsim$ set scexec_path C:/Users/user/AppData/ExcludedApp/scexec.node
SCEXEC Node Load Path Set to : C:/Users/user/AppData/ExcludedApp/scexec.node

Agent Features

For more information on Agent features click here

Client Features

For more information on Client features click here

🧙‍♂️ Deploy Illusions

First you need to identify a vulnerable Electron application which does not do ASAR security integrity checks such as Microsoft Teams. Newer applications may have integrity checks preventing backdooring. Older versions of the target app are more likely to be vulnerable.

  • Guide for Discovering Vulnerable Electron Apps

Simple Instructions

You don't need to compile the agent when backdooring Electron apps. Just replace the contents of {ELECTRONAPP}/resources/app/ with the Loki agent files.

Download Tool