
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns ๐ฌ.
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/6811/940f10b95a01139c7b1cc39bf8ae5bcd5ef094463607a758d96c0131fe5c5734.jpg" alt="@nodesecure/js-x-ray">
</p>
<p align="center">
<a href="https://github.com/NodeSecure/js-x-ray">
<img src="https://img.shields.io/badge/dynamic/json.svg?style=for-the-badge&url=https://raw.githubusercontent.com/NodeSecure/js-x-ray/refs/heads/master/workspaces/js-x-ray/package.json&query=$.version&label=Version" alt="npm version">
</a>
<a href="https://github.com/NodeSecure/js-x-ray/blob/master/LICENSE">
<img src="https://img.shields.io/github/license/NodeSecure/js-x-ray.svg?style=for-the-badge" alt="license">
</a>
<a href="https://api.securityscorecards.dev/projects/github.com/NodeSecure/js-x-ray">
<img src="https://api.securityscorecards.dev/projects/github.com/NodeSecure/js-x-ray/badge?style=for-the-badge" alt="ossf scorecard">
</a>
<a href="https://slsa.dev/spec/v1.0/levels#build-l3">
<img src="https://img.shields.io/badge/SLSA-level%203-green?style=for-the-badge&logo=data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAA4AAAAOCAMAAAAolt3jAAAABGdBTUEAALGPC/xhBQAAACBjSFJNAAB6JgAAgIQAAPoAAACA6AAAdTAAAOpgAAA6mAAAF3CculE8AAABMlBMVEXvMQDvMADwMQDwMADwMADvMADvMADwMADwMQDvMQDvMQDwMADwMADvMADwMADwMADwMQDvMQDvMQDwMQDvMQDwMQDwMADwMADwMQDwMADwMADvMADvMQDvMQDwMADwMQDwMADvMQDwMADwMQDwMADwMADwMADwMADwMADwMADvMQDvMQDwMADwMQDwMADvMQDvMQDwMADvMQDvMQDwMADwMQDwMQDwMQDvMQDwMADvMADwMADwMQDvMQDwMADwMQDwMQDwMQDwMQDvMQDvMQDvMADwMADvMADvMADvMADwMQDwMQDvMADvMQDvMQDvMADvMADvMQDwMQDvMQDvMADvMADvMADvMQDwMQDvMQDvMQDvMADvMADwMADvMQDvMQDvMQDvMADwMADwMQDwMAAAAAA/HoSwAAAAY3RSTlMpsvneQlQrU/LQSWzvM5DzmzeF9Pi+N6vvrk9HuP3asTaPgkVFmO3rUrMjqvL6d0LLTVjI/PuMQNSGOWa/6YU8zNuDLihJ0e6aMGzl8s2IT7b6lIFkRj1mtvQ0eJW95rG0+Sid59x/AAAAAWJLR0Rltd2InwAAAAlwSFlzAAAOwwAADsMBx2+oZAAAAAd0SU1FB+YHGg0tGLrTaD4AAACqSURBVAjXY2BgZEqGAGYWVjYGdg4oj5OLm4eRgZcvBcThFxAUEk4WYRAVE09OlpCUkpaRTU6WY0iWV1BUUlZRVQMqUddgSE7W1NLS1gFp0NXTB3KTDQyNjE2Sk03NzC1A3GR1SytrG1s7e4dkBogtjk7OLq5uyTCuu4enl3cyhOvj66fvHxAIEmYICg4JDQuPiAQrEmGIio6JjZOFOjSegSHBBMpOToxPAgCJfDZC/m2KHgAAACV0RVh0ZGF0ZTpjcmVhdGUAMjAyMi0wNy0yNlQxMzo0NToyNCswMDowMC8AywoAAAAldEVYdGRhdGU6bW9kaWZ5ADIwMjItMDctMjZUMTM6NDU6MjQrMDA6MDBeXXO2AAAAGXRFWHRTb2Z0d2FyZQB3d3cuaW5rc2NhcGUub3Jnm+48GgAAAABJRU5ErkJggg==" alt="slsa level3">
</a>
<a href="https://github.com/NodeSecure/js-x-ray/actions?query=workflow%3A%22Node.js+CI%22">
<img src="https://img.shields.io/github/actions/workflow/status/NodeSecure/js-x-ray/node.js.yml?style=for-the-badge" alt="github ci workflow">
</a>
</p>
**JS-X-Ray** is a JavaScript & TypeScript [SAST](https://github.com/resources/articles/what-is-sast) for identifying malicious patterns, security vulnerabilities, and code anomalies. Think of it as ESLint, but dedicated to security analysis. Originally created for [NodeSecure CLI](https://github.com/NodeSecure/cli), JS-X-Ray has become an independent and serious option for supply chain protection.
## ๐ How It Works
JS-X-Ray parses JS or TS code into an **Abstract Syntax Tree (AST)** with no extensive usage of RegEx or Semgrep rules. This enables variable tracing, dynamic import resolution, and detection of sophisticated obfuscation that pattern-matching tools miss. The tradeoff is that JS-X-Ray is purely dedicated to the JavaScript/TypeScript ecosystem.
## ๐ก Features
- Track `require()`, `import`, and dynamic imports with full variable tracing
- Detect obfuscated code and identify the tool used (jsfuck, jjencode, obfuscator.io, and more)
- Flag malicious patterns: data exfiltration, `process.env` serialization, unsafe shell commands
- Detect vulnerable code: `eval()`, `Function()` constructor, ReDoS-prone regexes, SQL injection
- Flag weak cryptographic algorithms (MD5, SHA1, etc.)
- Extract infrastructure indicators: URLs, IPs, hostnames, emails
- Configurable sensitivity modes (conservative/aggressive) and extensible probe system
- Supports both JavaScript and TypeScript
## ๐ Getting Started
These packages are available in the Node package repository and can be easily installed with [npm](https://docs.npmjs.com/getting-started/what-is-npm) or [yarn](https://yarnpkg.com).
```bash
$ npm i @nodesecure/js-x-ray
# or
$ yarn add @nodesecure/js-x-ray
```
## ๐ Usage
```js
import { AstAnalyser } from "@nodesecure/js-x-ray";
const scanner = new AstAnalyser();
const { warnings, dependencies } = await scanner.analyseFile("./file.js");
console.log(dependencies);
console.dir(warnings, { depth: null });
```
For the full API documentation, warning catalog, and advanced usage, see the [@nodesecure/js-x-ray package README](https://github.com/nodesecure/js-x-ray/blob/master/workspaces/js-x-ray/README.md).
## Workspaces
- [@nodesecure/js-x-ray](https://github.com/nodesecure/js-x-ray/blob/master/workspaces/js-x-ray)
- [@nodesecure/js-x-ray-ai](https://github.com/nodesecure/js-x-ray/blob/master/workspaces/js-x-ray-ai)
## ๐ฅ Contributors guide
If you are a developer **looking to contribute** to the project, you must first read the [CONTRIBUTING](https://github.com/nodesecure/js-x-ray/blob/master/CONTRIBUTING.md) guide.
Once you have finished your development, check that the tests (and linter) are still good by running the following script:
```bash
$ npm run check
```
> [!CAUTION]
> In case you introduce a new feature or fix a bug, make sure to include tests for it as well.
### Internal APIs
For contributors working on the JS-X-Ray internals, the following resources document low-level utilities and AST manipulation patterns:
- [ESTree utilities](https://github.com/nodesecure/js-x-ray/blob/master/workspaces/js-x-ray/src/estree/README.md) - Low-level helpers to manipulate ESTree AST nodes
- [ESTree assignment and declaration patterns (french)](https://github.com/nodesecure/js-x-ray/blob/master/workspaces/js-x-ray/docs/estree/patterns-french.md) - Reference guide for JavaScript assignment and declaration patterns in AST form
### Benchmarks
The performance of js-x-ray is measured and tracked using [mitata](https://github.com/evanwashere/mitata).
To run the benchmarks:
1. Navigate to `workspaces/js-x-ray`.
2. Run `npm run bench`.
The benchmark results are stored in workspaces/js-x-ray/benchmark/report.json. Do not edit this file manually; it is automatically updated on every pull request.
## Contributors โจ
<!-- ALL-CONTRIBUTORS-BADGE:START - Do not remove or modify this section -->
[](#contributors-)
<!-- ALL-CONTRIBUTORS-BADGE:END -->
Thanks goes to these wonderful people ([emoji key](https://allcontributors.org/docs/en/emoji-key)):
<!-- ALL-CONTRIBUTORS-LIST:START - Do not remove or modify this section -->
<!-- prettier-ignore-start -->
<!-- markdownlint-disable -->
<table>
<tbody>
<tr>
<td align="center" valign="top" width="14.28%"><a href="https://www.linkedin.com/in/thomas-gentilhomme/"><img src="https://assets.kitploit.com/production/public/readmes/6811/4cd37b340ac5be90ccc55e5a21f2d9c82501ab56dbde1e57d0daadbc6e0cb2ce.jpg" width="100px;" alt="Gentilhomme"/><br /><sub><b>Gentilhomme</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=fraxken" title="Code">๐ป</a> <a href="https://github.com/NodeSecure/js-x-ray/commits?author=fraxken" title="Documentation">๐</a> <a href="https://github.com/NodeSecure/js-x-ray/pulls?q=is%3Apr+reviewed-by%3Afraxken" title="Reviewed Pull Requests">๐</a> <a href="#security-fraxken" title="Security">๐ก๏ธ</a> <a href="https://github.com/NodeSecure/js-x-ray/issues?q=author%3Afraxken" title="Bug reports">๐</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/Rossb0b"><img src="https://assets.kitploit.com/production/public/readmes/6811/290540e07b7d409da77d9160c5c281ae5429576f8cde07d371402285ba38203e.jpg" width="100px;" alt="Nicolas Hallaert"/><br /><sub><b>Nicolas Hallaert</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=Rossb0b" title="Documentation">๐</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/antoine-coulon"><img src="https://assets.kitploit.com/production/public/readmes/6811/7e7a059e09744c2aa49bdf25f29042f76695ce0767dedc59e0e6cb09f8774572.png" width="100px;" alt="Antoine"/><br /><sub><b>Antoine</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=antoine-coulon" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/Mathieuka"><img src="https://assets.kitploit.com/production/public/readmes/6811/3f593de0aa9ba71939243c6567a8a9822a96523772a175bdb9e4f24a1f811b3e.png" width="100px;" alt="Mathieu"/><br /><sub><b>Mathieu</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=Mathieuka" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/Kawacrepe"><img src="https://assets.kitploit.com/production/public/readmes/6811/fabc77fc6d92a5aec450e91e4e9da49fa3eea3bd1ce939d45bd4b3c91ad99ab6.png" width="100px;" alt="Vincent Dhennin"/><br /><sub><b>Vincent Dhennin</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=Kawacrepe" title="Code">๐ป</a> <a href="https://github.com/NodeSecure/js-x-ray/commits?author=Kawacrepe" title="Tests">โ ๏ธ</a></td>
<td align="center" valign="top" width="14.28%"><a href="http://tonygo.dev"><img src="https://assets.kitploit.com/production/public/readmes/6811/426b7c43cd641123f5724c591b122e6b941121b9cc7f0890baf0862ac858d446.jpg" width="100px;" alt="Tony Gorez"/><br /><sub><b>Tony Gorez</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=tony-go" title="Code">๐ป</a> <a href="https://github.com/NodeSecure/js-x-ray/commits?author=tony-go" title="Documentation">๐</a> <a href="https://github.com/NodeSecure/js-x-ray/commits?author=tony-go" title="Tests">โ ๏ธ</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/PierreDemailly"><img src="https://assets.kitploit.com/production/public/readmes/6811/ac719b8fca5023e17c5c5dece208afd91a929a0ccba1d62835273c8c7f4db0b9.jpg" width="100px;" alt="PierreD"/><br /><sub><b>PierreD</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=PierreDemailly" title="Tests">โ ๏ธ</a> <a href="https://github.com/NodeSecure/js-x-ray/commits?author=PierreDemailly" title="Code">๐ป</a></td>
</tr>
<tr>
<td align="center" valign="top" width="14.28%"><a href="https://www.linkedin.com/in/franck-hallaert/"><img src="https://assets.kitploit.com/production/public/readmes/6811/3013b870b7192499f89b4a87e3d96431faf463f55984973a67d5483123cd9096.png" width="100px;" alt="Franck Hallaert"/><br /><sub><b>Franck Hallaert</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=Aekk0" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://maji.kiwi"><img src="https://assets.kitploit.com/production/public/readmes/6811/f6fdc6cf1d35ea5bb25a312eb31af0f0af894e0e6c9017863bd6a3f253a8a196.jpg" width="100px;" alt="Maji"/><br /><sub><b>Maji</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=M4gie" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/targos"><img src="https://assets.kitploit.com/production/public/readmes/6811/f9372734fe2cdf90a936c3ad3c8c22546fbfe4fa461bdc78ff3917c46c87ffbd.jpg" width="100px;" alt="Michaรซl Zasso"/><br /><sub><b>Michaรซl Zasso</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=targos" title="Code">๐ป</a> <a href="https://github.com/NodeSecure/js-x-ray/issues?q=author%3Atargos" title="Bug reports">๐</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/fabnguess"><img src="https://assets.kitploit.com/production/public/readmes/6811/02cb1e50333501a21d5a3d8fee1af11b5602466090339ca1e64c5967dd78eb32.jpg" width="100px;" alt="Kouadio Fabrice Nguessan"/><br /><sub><b>Kouadio Fabrice Nguessan</b></sub></a><br /><a href="#maintenance-fabnguess" title="Maintenance">๐ง</a> <a href="https://github.com/NodeSecure/js-x-ray/commits?author=fabnguess" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/jean-michelet"><img src="https://assets.kitploit.com/production/public/readmes/6811/171c0a72dc84d78015f34c1a27804761d30db515c6a749162ab2dfd01d48b803.png" width="100px;" alt="Jean"/><br /><sub><b>Jean</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=jean-michelet" title="Tests">โ ๏ธ</a> <a href="https://github.com/NodeSecure/js-x-ray/commits?author=jean-michelet" title="Code">๐ป</a> <a href="https://github.com/NodeSecure/js-x-ray/commits?author=jean-michelet" title="Documentation">๐</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/tchapacan"><img src="https://assets.kitploit.com/production/public/readmes/6811/b2577a3a5dde242c30287bc406b10595bbf4d2b68b925d9ea914e60960c8f173.png" width="100px;" alt="tchapacan"/><br /><sub><b>tchapacan</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=tchapacan" title="Code">๐ป</a> <a href="https://github.com/NodeSecure/js-x-ray/commits?author=tchapacan" title="Tests">โ ๏ธ</a></td>
<td align="center" valign="top" width="14.28%"><a href="http://miikkak.dev"><img src="https://assets.kitploit.com/production/public/readmes/6811/aa738edc908c21ad46f32f76ea9e03bcaef209237319990d68768c8b5474fe36.png" width="100px;" alt="mkarkkainen"/><br /><sub><b>mkarkkainen</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=mkarkkainen" title="Code">๐ป</a></td>
</tr>
<tr>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/FredGuiou"><img src="https://assets.kitploit.com/production/public/readmes/6811/c6a0b73221dfc270dca0165d535469ee75252d59b3cfabea8ccddd8966c7b1b6.png" width="100px;" alt="FredGuiou"/><br /><sub><b>FredGuiou</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=FredGuiou" title="Documentation">๐</a> <a href="https://github.com/NodeSecure/js-x-ray/commits?author=FredGuiou" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/madina0801"><img src="https://assets.kitploit.com/production/public/readmes/6811/4d91a94e780116f1f1adec6e2ecc277cc97d21301ae064d2cb22cddcab69928a.jpg" width="100px;" alt="Madina"/><br /><sub><b>Madina</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=madina0801" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/sairuss7"><img src="https://assets.kitploit.com/production/public/readmes/6811/46dcd3a528d54419536728639bf960e014183e53a35ff81effd5600f28b11035.gif" width="100px;" alt="SairussDev"/><br /><sub><b>SairussDev</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=sairuss7" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/fless-lab"><img src="https://assets.kitploit.com/production/public/readmes/6811/156dd8804faceafa89945da60fad81f30425e2c381e579b25f63623f944e4606.jpg" width="100px;" alt="Abdou-Raouf ATARMLA"/><br /><sub><b>Abdou-Raouf ATARMLA</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=fless-lab" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://clementgombauld.netlify.app/"><img src="https://assets.kitploit.com/production/public/readmes/6811/e754a09bed6a986acd4ff19c9190904c410d00b1352ebb16129d753c7abd327a.png" width="100px;" alt="Clement Gombauld"/><br /><sub><b>Clement Gombauld</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=clemgbld" title="Code">๐ป</a> <a href="https://github.com/NodeSecure/js-x-ray/commits?author=clemgbld" title="Tests">โ ๏ธ</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/intincrab"><img src="https://assets.kitploit.com/production/public/readmes/6811/166e2e53ef3d57b49000068104aa689fa6e4e499d1e6d003fc47d8f50ea9db6b.jpg" width="100px;" alt="Ajฤy "/><br /><sub><b>Ajฤy </b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=intincrab" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://michael.mior.ca"><img src="https://assets.kitploit.com/production/public/readmes/6811/07f6f242f2291de36fea9c2c4758360797b23bd0c576ef1a4e090f0bbffdc46b.jpg" width="100px;" alt="Michael Mior"/><br /><sub><b>Michael Mior</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=michaelmior" title="Documentation">๐</a></td>
</tr>
<tr>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/7amed3li"><img src="https://assets.kitploit.com/production/public/readmes/6811/b0f4f44f63f0c0899493ef70808c71af29d81c25693b763c1941534664ac5db0.png" width="100px;" alt="Hamed Mohamed"/><br /><sub><b>Hamed Mohamed</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=7amed3li" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/bashlor"><img src="https://assets.kitploit.com/production/public/readmes/6811/a54a13cb147aab71737f61581fc5fa16548c3e8dcb7ea1ff89c7fc00f06a14dd.jpg" width="100px;" alt="Elie Patrice"/><br /><sub><b>Elie Patrice</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=bashlor" title="Tests">โ ๏ธ</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://securityinit.tistory.com/"><img src="https://assets.kitploit.com/production/public/readmes/6811/7781b0eeafbb664fcd1a709f6f26e0472e8cdd5288e63340522a636cee75e5dd.png" width="100px;" alt="HoyeongJeon"/><br /><sub><b>HoyeongJeon</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=HoyeongJeon" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/Anne-Flower"><img src="https://assets.kitploit.com/production/public/readmes/6811/cb05570f7b2d94a65046f2b55b9a18be0d9cfd114807c6472ba30ca33874a2dd.png" width="100px;" alt="Anne-Flore"/><br /><sub><b>Anne-Flore</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=Anne-Flower" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://reshampokhrel.com.np/"><img src="https://assets.kitploit.com/production/public/readmes/6811/a6c3514b59f880aec0da8ec46733a9a85d09befb10b85902414e62bacb78136b.jpg" width="100px;" alt="Resham"/><br /><sub><b>Resham</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=presham" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/ErwanRaulo"><img src="https://avatars.githubusercontent.com/u/22614778?v=4%3Fs=100" width="100px;" alt="Erwan Raulo"/><br /><sub><b>Erwan Raulo</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=ErwanRaulo" title="Code">๐ป</a></td>
<td align="center" valign="top" width="14.28%"><a href="https://github.com/VictorMartins3"><img src="https://avatars.githubusercontent.com/u/106573420?v=4%3Fs=100" width="100px;" alt="Victor Martins"/><br /><sub><b>Victor Martins</b></sub></a><br /><a href="https://github.com/NodeSecure/js-x-ray/commits?author=VictorMartins3" title="Code">๐ป</a></td>
</tr>
</tbody>
</table>
<!-- markdownlint-restore -->
<!-- prettier-ignore-end -->
<!-- ALL-CONTRIBUTORS-LIST:END -->
## License
MIT