Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
JShunter — jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive data, such as API endpoints and potential security vulnerabilities, making it an essential resource for and bug bounty hunters and security researchers. | Kitploit
Tools/GitHubGitHub/cc1a2b/jshunter
ReconnaissanceStatic Code Analysis (SAST)Vulnerability AnalysisDynamic Code Analysis (DAST)WAF BypassWeb SecurityPenetration TestingSecret DetectionAPI Security
GitHubcc1a2b/jshunter

JShunter

View Repository
529593618 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive data, such as API endpoints and potential security vulnerabilities, making it an essential resource for and bug bounty hunters and security researchers.

Share

JSHunter

License Go Version Release GitHub stars Platform

Professional JavaScript Security Analysis Tool

Complete endpoint discovery, sensitive data detection, and advanced code analysis for security professionals

About

JSHunter is a comprehensive command-line tool for JavaScript security analysis and endpoint discovery. Built for security professionals, penetration testers, and developers, it delivers enterprise-grade analysis capabilities with high accuracy detection algorithms and professional reporting features.

https://github.com/user-attachments/assets/5a5f60fa-f8dc-4aac-bd06-2e93779f9af4

JSHunter in action — a real terminal capture of the CLI (every secret shown is fake test data)


Table of Contents

  • About
  • Features
  • Installation
  • Quick Start
  • Usage Examples
  • Command Reference
  • Advanced Usage
  • Contributing
  • License
  • Support

Features

Core Capabilities

  • Comprehensive Endpoint Discovery: Automatically extracts URLs, API endpoints, and hidden parameters from JavaScript files
  • Advanced Security Analysis: Identifies API keys, JWT tokens, credentials, and potential vulnerabilities with high accuracy
  • Flexible Input Methods: Supports URLs, file lists, local files, stdin piping, and recursive discovery
  • High-Performance Architecture: Multi-threaded concurrent processing with intelligent rate limiting
  • Professional Stealth Features: Proxy support, custom headers, user-agent rotation, and bypass detection

Intelligent Detection Engine

Enterprise-grade accuracy with advanced analysis algorithms

  • Smart Base64 Detection: High-accuracy filtering eliminates false positives from media content and encoded data
  • Professional Interface: Enterprise-ready terminology, documentation, and comprehensive reporting formats
  • Context-Aware Analysis: Advanced algorithms distinguish real security tokens from encoded media data
  • Entropy Analysis: Mathematical algorithms identify genuine security tokens and credentials with precision

Structural Detection Engine

JSHunter parses the JavaScript it scans instead of only pattern-matching it. A single-pass ECMAScript scanner classifies every byte of the response as string literal, template literal, comment, regular-expression literal, or code, and the detection rules are evaluated against that classification.

This matters because a regex has no idea what it matched. The same forty base64 characters mean "credential" inside a string literal, "chunk hash" inside a minified identifier, and nothing at all when they straddle the seam between two adjacent tokens. Knowing which one it is replaces a pile of proximity heuristics with a structural answer:

  • Region gating: a match inside a regex literal is a pattern, not a value. A match that crosses a token boundary is not a single literal. A match in code is an identifier fragment. All three are rejected outright.
  • Binding context: instead of scanning a fixed window of characters for the word key, the engine recovers the identifier or property key the value is actually bound to — const stripeSecret = "..." reads very differently from {contentHash: "..."}, and a shape-only rule now requires that binding.
  • Sibling key-sets: the members of a Firebase web config, an Algolia search config, a Segment analytics config and a Supabase browser client are recognised by the shape of the object they sit in.
  • Value shape: digests, UUIDs, prose, paths, placeholders, and base64 that decodes to a PNG, a font, a JSON document or an English sentence are each identified for what they are.
  • Exposure classification: values the issuer publishes on purpose — Stripe publishable keys, Mapbox public tokens, Supabase anon JWTs read from their own role claim, Twilio SIDs — are classified rather than reported as leaks. --include-public reports them anyway.
  • File-relative surprisal: a character-transition model built from the file being scanned scores how unlike the rest of that file a candidate reads.

Every rejection is conditional on the body being confidently JavaScript or JSON. On anything else — a .env file, prose, raw HTML — the engine contributes evidence but never suppresses, so a misclassified input can never hide a secret. --no-structural turns the whole layer off and restores v0.7 behaviour.

Findings carry the reasoning as an evidence object in --json, --ndjson and the SARIF property bag:

"exposure": "secret",
"evidence": {
  "region": "string-literal",
  "role": "assignment",
  "bound_to": "awsAccessKeyId",
  "shape": "opaque-token",
  "charset": "alphanumeric",
  "signals": [
    {"name": "in-literal", "delta": 0.04, "detail": "value is a complete string-literal"},
    {"name": "credential-binding", "delta": 0.12, "detail": "bound to 'awsAccessKeyId'"}
  ]
}

--stats reports what each stage dropped, so the pipeline stays auditable.

Chunk Graph and Route Discovery

A modern application ships one entry bundle and several hundred lazily loaded chunks whose URLs are assembled at runtime from a manifest the bundler inlines. Nothing links to them, so a crawler never sees them. -G recovers that manifest and prints the full asset list and client route table:

$ jshunter -u https://target.example/_next/static/chunks/main-a1b2c3.js -G
[CHUNKS] https://target.example/...: next runtime, 214 chunks, 37 routes
[CHUNK]  https://target.example/...  https://target.example/_next/static/chunks/settings.11aa22bb33cc.js
[ROUTE]  https://target.example/...  /admin/users/:id

Supported runtimes: webpack 4 and 5 (__webpack_require__.u, miniCssF, jsonpScriptSrc), Next.js build manifests, Vite and Rollup (__vite__mapDeps, __vitePreload), plain dynamic import(), and route tables from React Router, Vue Router and Angular. Output is tab-separated and deduplicated, so it pipes straight back in as the input list of a follow-up scan:

jshunter -u https://target.example/main.js -G -q | awk -F'\t' '/^\[CHUNK\]/{print $3}' > chunks.txt
jshunter -l chunks.txt -s -j > findings.json

Professional HTTP & Networking Suite

Enterprise-Grade Network Configuration

Authentication & Headers:

  • Custom Headers (-H): Repeatable authentication headers and custom request headers
  • Cookie Management (-c): Session cookies for accessing protected resources
  • User-Agent Control (-U): Custom UA strings or file-based rotation for stealth

Performance & Reliability:

  • Rate Limiting (-R): Configurable request delays (milliseconds) to avoid detection
  • Smart Timeouts (-T): Custom timeout settings for different network conditions
  • Intelligent Retry (-y): Automatic retry mechanism with exponential backoff for failed requests

Professional Integration:

  • Proxy Support (-p): Full Burp Suite and custom proxy integration (HTTP/HTTPS/SOCKS5)
  • TLS Flexibility (-k): Optional certificate verification bypass for testing environments
  • Thread Control (-t): Configurable concurrent request handling for optimal performance
Download Tool