Scroll to top
Threat Intelligence Factor's research team tracks real-world phishing, impersonation and social-engineering campaigns as they happen. See All Reports →

Photographic Memory: How a Broken Image Can Deliver Malicious Code

By Guy Ushomirsky, Factor Security Research · 3 Mar 2026

Cross-site scripting attacks are usually associated with obvious markers — a stray <script> tag, an unexpected redirect. Factor's research team recently examined a technique that avoids those markers entirely, hiding executable code inside something as ordinary as a broken image.

  1. The Mechanism: An Image Tag That Runs Code

    The HTML <img> tag supports an onerror attribute, which the browser executes automatically when the image fails to load. That behavior is legitimate and widely used — for example, to display a placeholder graphic. It also means that any code placed inside onerror runs the moment a deliberately broken image URL is referenced:

    <img src="notfound.jpg" onerror="alert('Hacked!')">

    Because notfound.jpg does not exist, the browser triggers the onerror handler. In this minimal example, the payload is a visible alert box — but the technique places arbitrary JavaScript directly on the page without a script tag anywhere in sight.

  2. Obfuscating the Payload

    A plaintext alert('Hacked!') call is easy for both automated filters and manual review to catch. Attackers commonly obscure the payload using Base64 encoding paired with a function that decodes and executes it at runtime:

    • atob('...') decodes a Base64 string back into plain text.
    • eval() executes that decoded text as JavaScript.
    <img src="notfound.jpg" onerror="eval(atob('YWxlcnQoJ0hhY2tlZCEnKQ=='))">

    That string decodes to the same alert('Hacked!') call — but a pattern-matching filter looking for recognizable JavaScript keywords will not flag the encoded version.

  3. Why This Matters Beyond a Popup

    A proof-of-concept alert is harmless. The same mechanism, used with a different payload, can be used to steal session cookies or authentication tokens, hijack an active user session, inject fraudulent page content, launch a phishing prompt inside a trusted page, or stage further malware delivery. Because the technique hides inside a standard, everyday HTML element, it is easy to overlook in a manual code review and can slip past filters that are only looking for conventional script injection patterns.

  4. Detecting It in Practice

    This class of attack is detectable, but it requires analysis that looks at behavior rather than surface syntax — flagging encoded content that decodes into executable code, regardless of which HTML attribute carries it. Factor's research team continues to track obfuscation techniques like this one as part of its ongoing work identifying how attackers adapt to conventional defenses.

Image-based XSS attack concept