riffhack
blacksite-kits // web

WebHook Injector

Browser-based payload injection system. Works on any website, bypasses CSP and CORS.

Verified Vendor
24h Response
Secure Escrow
webinjectionbrowser

Operator Reviews

Verified Exploitations

Shadow_Op

Verified

UID: abc12

"Got domain admin in under 2 hours. The obfuscation completely bypassed their EDR."

Proof

exploitation_proof.png

File hash: 69d5903776e069833513038ed341eeae

Preview raw proof

Phantom_Hacker

Verified

UID: k7m3n

"Had some issues with Windows Defender but still got persistence. Keylogger works perfectly."

Proof

rat_screenshot.jpg

File hash: 0c7406664fa3077c4a9a535f424d7ecd

Preview raw proof

CyberGhost

Verified

UID: xyz78

"Worth every penny. Client was shocked at how quickly we got domain admin. Stealth features are next level."

Proof

domain_admin.png

File hash: 88d3def4703b8165c797816ba94d8b48

Preview raw proof

Shadow_Op

Verified

UID: abc12

"Got domain admin in under 2 hours. The obfuscation completely bypassed their EDR."

Proof

exploitation_proof.png

File hash: 69d5903776e069833513038ed341eeae

Preview raw proof

Phantom_Hacker

Verified

UID: k7m3n

"Had some issues with Windows Defender but still got persistence. Keylogger works perfectly."

Proof

rat_screenshot.jpg

File hash: 0c7406664fa3077c4a9a535f424d7ecd

Preview raw proof

CyberGhost

Verified

UID: xyz78

"Worth every penny. Client was shocked at how quickly we got domain admin. Stealth features are next level."

Proof

domain_admin.png

File hash: 88d3def4703b8165c797816ba94d8b48

WebHook Injector — blacksite-kits

This thing is beautiful. Inject anything into any website, completely undetectable.

How it works

I've been developing this for 3 years. It's a browser extension that can inject arbitrary JavaScript into any website, regardless of security policies. The beauty is in the execution - it runs in the context of the target site, so it has full access to everything.

Features

  • Universal injection - Works on any website, any framework
  • CSP bypass - Circumvents Content Security Policy restrictions
  • CORS bypass - Makes requests to any domain from any origin
  • Stealth mode - No network requests, no external dependencies
  • Payload flexibility - Inject any JS, CSS, HTML, or binary data

Real-world usage

  • Banking trojans - Inject keyloggers into online banking sites
  • Session hijacking - Steal authentication tokens and cookies
  • Form manipulation - Modify payment forms, redirect transactions
  • Data exfiltration - Extract sensitive information from web apps
  • Cryptocurrency theft - Target crypto exchanges and wallets

Technical details

  • Browser support - Chrome, Firefox, Edge, Safari
  • Injection methods - DOM manipulation, script injection, event hijacking
  • Persistence - Survives page reloads and navigation
  • Evasion - Bypasses common detection methods

What you get

  • Source code (JavaScript)
  • Installation instructions
  • Usage examples and documentation
  • 5 pre-built payloads
  • 30 days of support

Pricing

  • Basic: $1,200 - Extension + basic payloads
  • Advanced: $2,500 - All features + custom payloads
  • Source code: $5,000 - Full source + commercial license

This is some next-level shit. Don't waste my time if you're not serious.

Recent inquiries

No inquiries yet. Be the first to reach out using the contact form above.