
A JavaScript Obfuscator based on Cryptographic Indistinguishability Obfuscation techniques
This project does not achieve indistinguishability obfuscation. You should not be using this to product to protect secrets. It exists to deter reverse engineering, not prevent it
A JavaScript obfuscator designed to make code extremely difficult to read and analyze for both humans and LLMs. Written in TypeScript. Implements techniques from peer-reviewed cryptographic obfuscation research.
npm install
npm run build
# Basic usage
node dist/index.js input.js > output.js
# With target token budget (default: 2,000,000)
node dist/index.js --target-tokens 500000 input.js > output.js
# Minimal obfuscation (small output)
node dist/index.js --target-tokens 10000 input.js > output.js
# Maximum bloat (10M tokens)
node dist/index.js --target-tokens 10000000 input.js > output.js
# Using environment variable
INPUT_FILE=input.js node dist/index.js > output.js
# Help
node dist/index.js --help
| Option | Default | Description |
|---|---|---|
--target-tokens <n> | 2000000 | Target output size in tokens. Small inputs are bloated up to this limit. Large inputs produce less bloat to stay within budget. |
--help, -h | Show help message |
npm run build # Compile TypeScript to dist/
npm run start # Run the obfuscator (reads input.js)
npm run test # Run the test suite
npm run obfuscate-package # Run compatibility tests against npm packages
const { obfuscate } = require('./dist/obfuscator');
const code = 'function add(a, b) { return a + b; }';
const obfuscated = obfuscate(code);
// With options
const obfuscated = obfuscate(code, { targetTokens: 500000 });
The obfuscator applies 20 transforms across 4 phases. Each stage builds on the previous one.
| Order | Transform | File | Description |
|---|---|---|---|
| 1 | Anti-Debug Traps | transforms/antiDebug.ts | Injects eval("debugger") statements and 10-20 setInterval loops with prime-number intervals (5s-600s) that repeatedly trigger debugger breakpoints. Each instance uses unique encoded strings. |
| 2 | Punctured Program Tripwires | transforms/tripwires.ts | Embeds hidden checks comparing parameter hashes against secret values. 5 hash patterns (bitwise fingerprint, modular arithmetic, charCodeAt, numeric hash, typeof+length). Triggers silent state corruption, busy loops, or throws on secret inputs. [Paper 4] |
| 3 | LPN Noise Injection | transforms/noiseInjection.ts | Adds and cancels random noise through split paths in arithmetic computations. 6 patterns: add/sub, XOR, mul/div, split dual-variable, computed hash-chain, bit-rotate. Intermediate values are meaningless without tracing full cancellation. [Paper 7] |
| Order | Transform | File | Description |
|---|---|---|---|
| 4 | Control Flow Flattening | transforms/controlFlowFlattening.ts | Converts function bodies into while(true) { switch((_s * P) % M) { ... } } state machines with modular arithmetic dispatch — case values are encoded through (stateId * multiplier) % modulus using random prime parameters. [Paper 3] |
| 5 | Opaque Predicates | transforms/opaquePredicates.ts | Injects if conditions that always evaluate to true or false but are mathematically hard to prove (e.g., (x*x+x)%2===0). 15 predicate formulas across modular arithmetic, bitwise, and type-check categories. |
| 6 | Proxy Functions | transforms/proxyFunctions.ts | Routes all function calls through two dispatchers: _fc(fn, ...args) for simple calls, _mc(obj, prop, ...args) for method calls. Uses Function.prototype.apply captured in a local variable for resilience. |
| 7 | Context Window Exhaustion | transforms/contextExhaustion.ts | Wraps expressions in deeply nested ternaries with opaque conditions, void-expression chains, and conditional void padding. Forces LLMs to waste context window tokens on noise. |
| 8 | Comma Expression Merging | transforms/commaExpressions.ts | Collapses consecutive expression statements into single comma expressions: a(); b(); return c() becomes return a(), b(), c(). |
| Order | Pass | File | Description |
|---|---|---|---|
| 9 | Pass 1: Catalog | passes/firstPass.ts | Traverses the AST and catalogs every identifier, building a globals map that assigns each a random 6-16 character Unicode name drawn from 16 script ranges (CJK, Hangul, Greek, Cyrillic, Devanagari, Thai, Arabic, Katakana, etc.). |
| 10 | Pass 2: Substitute | passes/secondPass.ts | Replaces all identifier names with their obfuscated Unicode equivalents. Encodes require() arguments as String.fromCharCode(...). Encodes static import/export sources as unicode-escaped string literals. Substitutes class superClass references, template literal expressions, destructuring patterns. |
| 11 | Pass 3: Dummy Parameters | passes/thirdPass.ts | Injects 0-15 random unused parameters into every function declaration and expression. Skips functions with rest parameters. Strips all comments. |
| Order | Transform | File | Description |
|---|---|---|---|
| 12 | Global Variable Encoding | transforms/globalVariableEncoding.ts | Replaces references to globals (dynamically discovered from globalThis + window package) with eval("Name<suffix>".replace(new RegExp("<suffix>$"), "")). Both strings flow through the string array. |
| 13 | Property Key Encoding | transforms/propertyKeyEncoding.ts | Converts dot access to computed access with per-scope registries. Cross-scope access works because all suffixes resolve to the same property name at runtime via .replace(). |
| 14 | Number Encoding | transforms/numberEncoding.ts | 11 encoding strategies: shift+add, XOR identity, complement, division, nested shifts, double-NOT, modular, etc. Each instance uniquely generated. Skips property keys and switch case values. |
| 15 | Self-Integrity Verification | transforms/selfIntegrity.ts | Injects 2-4 runtime checks: eval native-code verification, Function.prototype.toString integrity, timing anomaly detection, code structure validation. Anti-tamper responses: busy wait, throw, silent corruption. [Paper 10] |
| 16 | String Array Extraction | transforms/stringArrayExtraction.ts | Collects all strings into a single array with chained XOR decryption (key for entry N depends on decoded content of entry N-1) and sparse position-dependent error patterns (each character gets a different XOR key, with LPN-inspired sparse errors at select positions). [Papers 2, 9] |
| 17 | Console Stubs | obfuscator.ts | Dynamically discovers all console methods and sets each to a no-op function. |
| 18 | Terser Minification | obfuscator.ts | Strips whitespace/formatting via terser (mangle: false, compress: false). Falls back to regex-based stripping if terser can't parse the output. |
Dead code is injected at multiple points with two generation strategies: