html-smuggling-lure - HTML Smuggling Lure for Initial Access
Embed base64-encoded payloads in HTML attachments that reconstruct and auto-download files via JavaScript Blob to bypass email gateway and proxy inspection.
Tags
Updated: 2026-06-30Capabilities
Typical Inputs
Typical Outputs
What this skill does
- encode payload to base64
- generate HTML smuggling page
- embed payload in HTML
- create JavaScript Blob
- trigger file download
- bypass email gateway
- bypass proxy inspection
- deliver via GoPhish
- fetch payload from URL
- obfuscate JavaScript code
Inputs
- compiled payload file
- GoPhish API key
- SMTP server access
- lure domain
Outputs
- HTML smuggling page
- base64-encoded payload
- email attachment
- downloaded payload file
Requirements
- Bash tool
- Read tool
- Write tool
- Python environment
- base64 utility
- GoPhish instance or SMTP server
