PDF with embedded JavaScript auto-executing on open
Attackers routinely weaponize PDFs by embedding JavaScript that executes automatically when the document is opened, delivering payloads or phishing lures without any interaction beyond the open action. Malicious scripts can exploit viewer vulnerabilities, trigger external downloads, or exfiltrate local data — behavior aligned with script-based execution techniques such as T1218.001. This demo presents a PDF carrying a benign app.alert script to illustrate the risk without any malicious payload. Deep CDR (Content Disarm and Reconstruction) parses the file, removes all active content including JavaScript, and rebuilds a clean, fully functional PDF that preserves the document's appearance while eliminating the attack surface.
Attack Technique
PDF embedded JavaScript
MITRE ATT&CK
T1218.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗