Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
jsleak — Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and URL status checking. | Kitploit
Tools/GitHubGitHub/byt3hx/jsleak
ReconnaissanceInformation GatheringWeb SecuritySecret Detection
GitHubbyt3hx/jsleak

jsleak

Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and URL status checking.

View Repository
59369511 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Description

I was developing jsleak during most of my free time for my own need.It is easy-to-use command-line tool designed to uncover secrets and links in JavaScript files or source code. The jsleak was inspired by Linkfinder and regexes are collected from multiple sources.

Features:

  • Discover secrets in JS files such as API keys, tokens, and passwords.
  • Identify links in the source code.
  • Complete Url Function
  • Concurrent processing for scanning of multiple Urls
  • Check status code if the url is alive or not

Latest Update

Jsleak now supports regex patterns from secrets-patterns-db https://github.com/mazen160/secrets-patterns-db.

If you want to use your own custom regex patterns, you can place them in a YAML file following the template below.

root@kitploit:~
patterns:
  - pattern:
      name: Amazon MWS Auth Token
      regex: "amzn\\.mws\\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}"
      confidence: low

Installation

If you are using old version of golang (go 1.15, 1.16) , use the following command to install jsleak.

root@kitploit:~
go get github.com/channyein1337/jsleak

If you are using latest version of go (1.17+) , use the following command to install.

root@kitploit:~
go install github.com/channyein1337/jsleak@latest

Usage

Choose a YAML file from the secrets-patterns-db. If you’re not sure which one to pick, consider using: https://raw.githubusercontent.com/mazen160/secrets-patterns-db/refs/heads/master/datasets/trufflehog-v3.yaml

Run jsleak with Your Selected Regex File

root@kitploit:~
echo "http://testphp.vulnweb.com/" | jsleak -t trufflehog-v3.yaml -s

To display help message

root@kitploit:~
jsleak -h

Secret Finder

root@kitploit:~
echo http://testphp.vulnweb.com/ | jsleak  -t secret.yaml -s

Link Finder

root@kitploit:~
echo http://testphp.vulnweb.com/ | jsleak -l

Complete Url

root@kitploit:~
echo http://testphp.vulnweb.com/ | jsleak -e

Check Status

root@kitploit:~
echo http://testphp.vulnweb.com/ | jsleak -c 20 -k

You can also use multiple flags

root@kitploit:~
echo http://testphp.vulnweb.com/ | jsleak -c 20 -l -s 

Running with Urls

root@kitploit:~
cat urls.txt | jsleak -l -s -c 30

To Do

  • Scan secret on completeURL with 200 response.
  • Add Version flag.
  • Support scanning local files.
  • Support scanning apk files.
  • Update Regex.
  • Support mulitple user agents.
  • Support color output

Credit and thanks to all the following resources

  • https://github.com/GerbenJavado/LinkFinder
  • https://github.com/0xsha/GoLinkFinder
Download Tool