Join our Newsletter — 33% off our NHI Course

JavaScript Credential Harvesting

A browser-side technique that captures usernames and passwords by injecting malicious script into a login page. In this article’s context, the script hooks form submissions on Outlook Web Access and sends captured credentials to an external channel, turning a normal sign-in page into an interception point.

How JavaScript credential harvesting works

JavaScript credential harvesting turns the browser into the collection point. By injecting script into a legitimate login page, an attacker can watch form events, capture what the user submits, and pass the data out before the session is even established. In the Outlook Web Access example, the login page still looks normal to the user, which makes the interception especially effective.

The important security detail is that the technique abuses the trust boundary inside the page itself. Rather than stealing passwords from a server or a network link, the malicious code operates where the user is already expected to type secrets, so the attack can capture both usernames and passwords with very little visible disruption. That makes it closely related to web compromise, script injection, and secret exfiltration rather than to ordinary password guessing.

Where the attack sits in the broader threat landscape

This technique is usually part of a larger intrusion path, not a standalone trick. Attackers first need a way to alter the page, such as compromised web content, injected script, a malicious extension, a supply-chain compromise, or another form of client-side execution. Once the script runs, the attacker gains a high-value opportunity to intercept secrets at the moment of entry, which is often more useful than trying to crack them later.

Because the payload runs in the browser, defenders may miss it if they only look for server-side indicators of compromise. The danger is not just password theft, but downstream abuse of the captured session entry point, including account takeover, lateral movement through trusted mail or collaboration systems, and reuse of the stolen secrets elsewhere.

Why it matters for authentication and secret protection

Credential harvesting is effective because passwords are still a primary authentication factor in many environments, and browser-based login flows remain a common place to collect them. Once the user submits the form, the attacker can relay the secrets to an external channel almost immediately. That means the window for detection can be short, especially if the login page itself has been altered to behave normally.

For organisations, this is a reminder that protecting credentials is not only about password strength. It also depends on page integrity, script control, session protection, and limiting where secrets can be entered and observed. The same browser workflow that improves user convenience can become an interception surface when the page or its dependencies are compromised.

That is why credential exposure statistics are so concerning. NHI Mgmt Group’s Ultimate Guide to NHIs notes that 91.6% of secrets remain valid five days after notification, showing how long stolen secrets can stay useful after capture.

Defensive implications for web and identity teams

Defenders should treat any login page that can be script-altered as a sensitive trust boundary. The practical question is not only whether the authentication backend is strong, but whether the browser-side path is sufficiently controlled to prevent malicious code from observing submitted credentials. In environments like webmail, identity portals, and SaaS sign-in pages, the page itself becomes part of the authentication control surface.

That is why stronger secret hygiene, page integrity monitoring, and reduction of long-lived credentials matter together. If an attacker can harvest a password once, the value of the credential is determined by how quickly it can be invalidated, whether stronger authentication stops reuse, and how much access that password unlocks before detection.

For a broader view of how harvested credentials are used after collection, 52 NHI Breaches Analysis shows how credential theft frequently becomes an initial foothold for broader compromise, and OWASP Non-Human Identity Top 10 provides a useful control lens for secret handling and credential lifecycle discipline.

Risk and Threat Considerations

JavaScript credential harvesting is dangerous because it captures secrets at the exact moment a user trusts the page. The attacker does not need to break the password directly, only to place code in the login flow and quietly forward what the user types. That makes the technique attractive in browser compromise, phishing kits, injected web content, and supply-chain scenarios.

Failure mechanism: Malicious script hooks the form submission or input fields, copies credentials before transmission to the legitimate service, and exfiltrates them through an out-of-band channel that blends into normal web traffic.

Impact: Stolen credentials can enable immediate account takeover, mailbox access, session abuse, secondary phishing, and broader compromise of connected services that trust the same identity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Agentic AI Top 10 A1 — Prompt Injection and Input Trust Script injection on a login page exploits untrusted client-side input paths.
A5 — Credential and Secret Exposure The attack captures credentials in-browser before they reach the legitimate service.
Recommendation — Treat client-side script injection as a trust-boundary failure and restrict executable content on authentication pages. Harden secret handling and prevent pages from exposing credentials to injected code.
CIS Controls v8 8 — Audit Log Management Credential harvesting benefits from weak visibility into suspicious authentication-page activity.
16 — Application Software Security The technique depends on malicious code executing inside a web login flow.
Recommendation — Log and review authentication events and page-integrity changes to detect credential capture attempts. Secure web application delivery so login pages cannot be altered by injected script or compromised dependencies.
MITRE ATT&CK T1056.003 — Input Capture: Web Portal Capture The technique captures credentials from web login interactions in the browser.
T1056 — Input Capture The page hooks user input and steals secrets at entry time.
Recommendation — Map observed web credential theft to T1056.003 and hunt for altered login-page behavior. Detect input-capture behavior on authentication pages and investigate suspicious browser-side form interception.

Practitioner Guidance

What to watch for: Treat unexpected script changes on login pages, unusual form handlers, and new outbound destinations from authentication flows as high-priority signals. Browser-side credential theft often leaves little server-side evidence, so identity, web, and endpoint telemetry need to be reviewed together.

Governance implication: Organisations should regard login-page integrity as part of authentication assurance, not just application hygiene. If the page can be modified by untrusted script, the control fails before the password is ever checked.