Skip to content

Burpsuite Extender plugin that passively finds hidden URLs and endpoints in any downloaded Javascript files. Great for native Javascript applications such as Next.js, Node.js or Dapps frontends.

Notifications You must be signed in to change notification settings

smartauditorAI/burp-js-urlsucker

Repository files navigation

Intro

Burpsuite Extender plugin (Montoya version) that finds passively hidden endpoints and urls within any downloaded JavaScript file while browsing a website.

Based on previous Perl Script: https://github.com/defensahacker/URLSUCKER

To compile

make

Add dist/js-urlsucker-montoya.jar in Burpsuite Professional with Extensions -> Add, browse the previously js-urlsucker-montoya.jar compiled file and select. Done. There will appear a new tab called "URLSucker" where you can see the results.

(c) 2025 Defensahacker Labs

About

Burpsuite Extender plugin that passively finds hidden URLs and endpoints in any downloaded Javascript files. Great for native Javascript applications such as Next.js, Node.js or Dapps frontends.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published