Skip to content
Research Article Open access CC BY 4.0

Leveraging Machine Learning for the Identification of Obfuscated JavaScript in Phishing Attacks

Prince Chukwuemeka, Onwuegbuchunam Kyrian, Okes Imoni

Asian Journal of Research in Computer Science · pp. 301–314 · Published 9 Jun 2025

10.9734/ajrcos/2025/v18i6700

Abstract

JavaScript obfuscation has emerged as a pervasive tactic employed by cybercriminals to conceal malicious code and facilitate phishing attacks. As a language supported by over 95% of modern websites, JavaScript provides a fertile ground for exploitation due to its ubiquity and integration into nearly all web applications. Cyber attackers frequently rely on obfuscation techniques to disguise malicious scripts, thereby evading detection by traditional antivirus software and rendering manual code analysis exceedingly difficult. The complexity of modern obfuscation techniques demands advanced detection methodologies beyond signature-based tools. This research focuses on exploring the interplay between JavaScript obfuscation and phishing, identifying prevalent obfuscation methods, and deploying machine learning (ML) approaches to detect these threats. By leveraging supervised learning algorithms and semantic feature extraction, we demonstrate how ML can be utilized to distinguish between benign and malicious, obfuscated scripts. The study also conducts a comprehensive review of existing tools, methodologies, and academic research addressing this challenge. We propose a robust framework integrating abstract syntax tree (AST) analysis, lexical pattern recognition, and ensemble ML models for enhanced detection accuracy. Additionally, this study outlines key implementation strategies, challenges, and evaluation metrics while providing a critical outlook on future research pathways. The proposed approach promises significant advancements in cybersecurity by improving the precision of threat detection systems, thus reducing the risks posed by obfuscated phishing scripts in web applications.

JavaScript obfuscation phishing detection machine learning abstract syntax tree (AST) cybersecurity

Cited by 8

Machine learning-based flood inundation mapping and LULC classification in Ahoada West, Rivers State, Nigeria using satellite imagery

Meremu Dogiye Amos, Franklin N. Okeke, Ebingiye Nelvin Agbozu · Discover Geoscience · 2026

DRL, TF-IDF and SMOTE based Malicious URLs Detection and Classification

Nivaashini M, P. G., B. G · 2025 First International Conference of Advances in Engineering and Computing Technologies for Sustainable Development (AECTSD) · 2025

Predictive Modeling of Iron Concentration in Groundwater Using Machine Learning Techniques: A Case Study in Part of Yenagoa, Bayelsa State

Charles U. Akajiaku, Comfort Oyindamola Agbabiaka, Okes Imoni · Journal of Computational Systems and Applications · 2025

Showing 5 of 8 known citations — external sources report more than can currently be individually listed.

Article metrics

Real usage data collected on this platform.

0

Page views

0

PDF downloads

0

Outbound clicks

8

Citations

Views by country

Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".

No views recorded yet.

Traffic sources

Referring site, by host.

No traffic recorded yet.

Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.