Recently, Check Point Research (CPR) has been studying the use of compiled V8 JavaScript by malware authors. Compiled V8 JavaScript is a feature of V8, Google’s JavaScript engine, that allows JavaScript to be “compiled” into low-level bytecode. Hackers have begun to exploit this feature as it helps them evade static detection and hide source code.

To statically analyze compiled JavaScript files, the researchers used a custom tool called “View8,” which decompiles V8 bytecode into high-level readable language. The researchers used this tool to decompile thousands of compiled V8 applications, covering various types of malware (e.g., RATs, info-stealers, cryptominers, and ransomware).
Let's take a closer look at what compiled V8 JavaScript is and how it is used by hackers and malware creators.
V8engine
V8 is an open-source JavaScript engine developed by Google. It is written in C++ and is used in the Google Chrome, as well as in many other public projects (e.g. Node.js). As Check Point explains, V8 (Ignition) bytecode serves as an intermediate step in the JavaScript code optimization process. It allows the V8 engine to efficiently execute JavaScript.
See also: Turla Hackers: They use LNK files to transport malware
V8 also supports the ability to cache serialized bytecode for later execution by the interpreter. This feature is exploited by malware authors to hide the source code of the application.
V8 Compilation
To use this feature and “compile” plain JavaScript into serial V8 bytecode, the researchers noticed that they could use the built-in vm module in the Node.js platform. The vm.Script method takes two parameters: the first is the JavaScript code and the second is a dictionary of options.
You can see more about the “compilation” process here.
V8 execution
As compiled V8 bytecode is linked to the specific version for which it was compiled, attackers must ensure compatibility between the bytecode and the V8 engine for execution to be successful (details on how this is done can be found here).
View8 tool
View8 is a new static analysis tool for decompiling v8 bytecode into high-level readable code. This tool was developed by a member of Check Point Research. View8 takes a compiled file as an argument and produces a textual decompiled version in a language similar to JavaScript.
As mentioned earlier, the researchers used View8 and decompiled thousands of maliciously compiled files V8 The research uncovered various malware, including stealers, loaders, RATS, wipers, and ransomware. Most of them had very low detection scores on VirusTotal.
See also: Dark Web malware exposes 3,300 users linked to child abuse site
Additionally, various open-source JavaScript malware, such as TurkoRat, Vare-Stealer, and Mirai stealer, were detected, which were compiled by the attackers into V8 bytecode before distribution.
Use of compiled V8 JavaScript by malware creators
Some of the malware that exploited compiled V8 JavaScript are:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
ChromeLoader
ChromeLoader compromises browsers, steals sensitive information , and executes additional malicious payloads. The use of compiled V8 is particularly interesting, as the attackers embedded an encrypted V8 bytecode payload and invoked it using built-in NodeJS (vm.Script) methods.
Ransomware and Wipers
Researchers also identified a few ransomware. The structure was simple, involving a sequence of read, encrypt, and write operations. The malware starts with some configurations, including directories to encrypt, file extensions to target, and a Discord webhook that acts as a C&C. The malware then recursively iterates through all directories and encrypts them using the AES encryption algorithm.
Finally, the malware sends the victim's information back to the attacker using the Discord webhook.
A type of wiper malware was also found .

Shellcode Loader
Another malware detected and analyzed was a shellcode loader with the ability to download dynamic x64 shellcodes from a remote C&C server (+ ability to execute them).
More details about malware that exploits compiled V8 JavaScript can be found in the Check Point Research report
See also: KT accused of massive malware attack on customers
The above discoveries show that cybercriminals continue to devise new tricks to hide their attacks. The V8 exploit is not surprising, as this technology is commonly used to create software, so it can easily be used to create malware.
Malware protection
Using reliable and up-to-date antivirus is essential for protection against malware. Antivirus programs can detect and remove malicious software, as well as provide continuous real-time protection.
Regularly updating your operating system and software is also critical. Updates include security that close gaps that attackers could exploit.
Next is using strong and unique passwords for each account. Passwords should include a combination of letters, numbers, and special characters to make them harder to crack.
Enabling multi-factor authentication (MFA) adds an extra layer of security. Even if someone gets your password, they'll still need the second factor to gain access.
Finally, it is also very important to avoid clicking on suspicious links and attachments in emails and messages. Attackers often use phishing emails to trick users into installing malware on their computers.
Source: research.checkpoint.com
