Photographic Memory: How a Broken Image Can Deliver Malicious Code
By Guy Ushomirsky, Factor Security Research · 3 Mar 2026
Cross-site scripting attacks are usually associated with obvious markers — a stray <script> tag, an unexpected redirect. Factor's research team recently examined a technique that avoids those markers entirely, hiding executable code inside something as ordinary as a broken image.
-
The Mechanism: An Image Tag That Runs Code
The HTML
<img>tag supports anonerrorattribute, which the browser executes automatically when the image fails to load. That behavior is legitimate and widely used — for example, to display a placeholder graphic. It also means that any code placed insideonerrorruns the moment a deliberately broken image URL is referenced:<img src="notfound.jpg" onerror="alert('Hacked!')">Because
notfound.jpgdoes not exist, the browser triggers theonerrorhandler. In this minimal example, the payload is a visible alert box — but the technique places arbitrary JavaScript directly on the page without a script tag anywhere in sight. -
Obfuscating the Payload
A plaintext
alert('Hacked!')call is easy for both automated filters and manual review to catch. Attackers commonly obscure the payload using Base64 encoding paired with a function that decodes and executes it at runtime:atob('...')decodes a Base64 string back into plain text.eval()executes that decoded text as JavaScript.
<img src="notfound.jpg" onerror="eval(atob('YWxlcnQoJ0hhY2tlZCEnKQ=='))">That string decodes to the same
alert('Hacked!')call — but a pattern-matching filter looking for recognizable JavaScript keywords will not flag the encoded version. -
Why This Matters Beyond a Popup
A proof-of-concept alert is harmless. The same mechanism, used with a different payload, can be used to steal session cookies or authentication tokens, hijack an active user session, inject fraudulent page content, launch a phishing prompt inside a trusted page, or stage further malware delivery. Because the technique hides inside a standard, everyday HTML element, it is easy to overlook in a manual code review and can slip past filters that are only looking for conventional script injection patterns.
-
Detecting It in Practice
This class of attack is detectable, but it requires analysis that looks at behavior rather than surface syntax — flagging encoded content that decodes into executable code, regardless of which HTML attribute carries it. Factor's research team continues to track obfuscation techniques like this one as part of its ongoing work identifying how attackers adapt to conventional defenses.

