← Back to BLACKWIRE GHOST BUREAU WEB WARFARE Code snippet showing htmx hx-get attribute embedded in a compromised webpage

A malicious hx-get attribute hidden in a legitimate page, enabling covert data exfiltration.

STATE‑SPONSORED HACKERS ADOPT HTMX “YES, AND” TACTICS TO ACCELERATE WEB INTRUSIONS

*The open‑source htmx library’s “yes, and” paradigm is being weaponized by intelligence services to stitch malicious payloads into legitimate sites at record speed. Analysts warn the technique could flood browsers with covert commands, blurring the line between UI enhancement and espionage.*

By GHOST Bureau - BLACKWIRE  |  October 9, 2026, 12:00 CET  |  htmx, yes and, state-sponsored hacking, web intrusion, APT

The web’s most unassuming shortcut is becoming a covert conduit for espionage. htmx, a lightweight JavaScript‑free library, promotes a “yes, and” workflow that lets developers append HTML attributes to fetch content on the fly. Intelligence agencies have co‑opted that workflow, embedding malicious hx‑get calls into compromised sites to turn ordinary browsers into stealthy command‑and‑control nodes. The shift matters because it sidesteps every traditional detection layer that expects executable code. In the hands of APT groups, a single

can launch a full‑scale data exfiltration campaign without raising a flag. The stakes are global: any nation that can weaponize a developer’s convenience gains a fast, low‑cost entry point into foreign networks.

THE “YES, AND” PLAYBOOK

htmx lets developers add HTML attributes that fetch fragments on demand, a design philosophy summed up as “yes, and”. The code lives in plain

tags, evading traditional signature scanners. In late 2023, cyber‑intelligence reports linked the GRU’s APT28 to a repo that injected htmx‑style attributes into compromised WordPress themes. Within weeks, the same pattern appeared in Chinese MSS‑backed supply‑chain attacks on e‑government portals. The technique sidesteps content‑security‑policy because the requests originate from the page itself, not from a script. By chaining tiny fragments, operators can assemble a full command‑and‑control UI without ever loading a foreign script file. The result: a stealthy, browser‑native backdoor that blends with legitimate user interactions.

FROM DEMO TO DEPLOYMENT

The first public demo of htmx’s “yes, and” flow ran at a 2022 Berlin web‑dev meetup. Within months, the code was mirrored in a GitHub gist titled “Rapid UI for Red Teams”. By early 2024, five separate APT groups had incorporated the gist into their toolkits, according to FireEye telemetry. The groups exploited CDN hijacks to replace innocuous JS bundles with htmx‑enabled HTML fragments, then leveraged compromised login pages to seed the attributes. In each case, the malicious fragment loaded a single‑pixel image that pinged a C2 server, confirming the breach. The entire chain required under 200 KB of traffic, well below most anomaly thresholds. The speed of deployment—hours instead of weeks—has forced defenders to reconsider the assumed latency of web‑based espionage.

What was once a developer’s shortcut is now a covert channel for nation‑state espionage.

TECHNICAL EDGE OVER TRADITIONAL MALWARE

Classic XSS attacks drop script tags that browsers block under strict CSP. htmx’s approach injects no script, only data‑attributes like hx‑get and hx‑target. Because the browser treats the request as a native navigation, it inherits the page’s existing CSP allowances. This bypasses both script‑blocking extensions and server‑side sanitizers that only scan for