Connect with us

Hi, what are you looking for?


Email Security

Gmail to Block JavaScript File Attachments

Google’s G Suite team announced on Wednesday that, for security reasons, Gmail will soon stop allowing users to attach JavaScript (.js) files to emails.

Google’s G Suite team announced on Wednesday that, for security reasons, Gmail will soon stop allowing users to attach JavaScript (.js) files to emails.

Currently, there are more than two dozen potentially dangerous file types that can’t be used as attachments in Gmail, including .exe, .jar, .sys, .scr, .bat, .com, .vbs and .cmd. Starting on February 13, 2017, .js files will also be added to the list.

Users who attempt to attach these types of files will see a message informing them that the file has been blocked for security reasons. A “Help” link will be provided for people who may want additional information.

JavaScript files blocked in Gmail

For cases where users need to send .js files for legitimate reasons, Google recommends using Drive, Cloud Storage or other file-sharing services.

There have been several campaigns recently where attackers delivered malware by attaching JavaScript files to emails. For instance, the cybercriminals behind the Locky ransomware used JavaScript attachments to drop downloaders, and they later started directly embedding the malicious binary into the JavaScript file.

Ransomware has been increasingly using JavaScript (e.g. Ransom32, RAA) and significant spam campaigns delivering malicious .js files are not uncommon, which is probably why Google has decided to block these types of files.

Google made several security improvements to Gmail in the past year: it enhanced security alerts, it started flagging unauthenticated messages and potentially dangerous URLs, and it disabled support for the RC4 cipher and the SSLv3 protocol.

Advertisement. Scroll to continue reading.

Related: Google’s DLP for Gmail Adds Optical Character Recognition

Related: Phished Gmail Accounts Immediately Accessed by Hackers

Related: Students Sue Google over Gmail Account Scanning

Written By

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence.


Securityweek’s CISO Forum will address issues and challenges that are top of mind for today’s security leaders and what the future looks like as chief defenders of the enterprise.


Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

Management & Strategy

SecurityWeek examines how a layoff-induced influx of experienced professionals into the job seeker market is affecting or might affect, the skills gap and recruitment...

CISO Conversations

In this issue of CISO Conversations we talk to two CISOs about solving the CISO/CIO conflict by combining the roles under one person.

CISO Strategy

Security professionals understand the need for resilience in their company’s security posture, but often fail to build their own psychological resilience to stress.

Management & Strategy

Industry professionals comment on the recent disruption of the Hive ransomware operation and its hacking by law enforcement.

Cloud Security

Microsoft and Proofpoint are warning organizations that use cloud services about a recent consent phishing attack that abused Microsoft’s ‘verified publisher’ status.

Management & Strategy

Tens of cybersecurity companies have announced cutting staff over the past year, in some cases significant portions of their global workforce.