Most attacks will use some infrastructure components to target or exfiltrate data. Those components are more know in source code as URLs and IPs.
Right now that's probably impossible to achieve without implementing new abstraction in JS-X-Ray: NodeSecure/js-x-ray#425