Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
egodeath — A JavaScript Obfuscator based on Cryptographic Indistinguishability Obfuscation techniques | Kitploit
Tools/GitHubGitHub/nstarke/egodeath
Static AnalysisCode AnalysisReverse EngineeringPapers & ResearchLearning & Education
GitHubnstarke/egodeath

egodeath

A JavaScript Obfuscator based on Cryptographic Indistinguishability Obfuscation techniques

View Repository
535149 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

egodeath

This project does not achieve indistinguishability obfuscation. You should not be using this to product to protect secrets. It exists to deter reverse engineering, not prevent it

Tests

images/screenshot.png A JavaScript obfuscator designed to make code extremely difficult to read and analyze for both humans and LLMs. Written in TypeScript. Implements techniques from peer-reviewed cryptographic obfuscation research.

Installation

npm install
npm run build

CLI Usage

# Basic usage
node dist/index.js input.js > output.js

# With target token budget (default: 2,000,000)
node dist/index.js --target-tokens 500000 input.js > output.js

# Minimal obfuscation (small output)
node dist/index.js --target-tokens 10000 input.js > output.js

# Maximum bloat (10M tokens)
node dist/index.js --target-tokens 10000000 input.js > output.js

# Using environment variable
INPUT_FILE=input.js node dist/index.js > output.js

# Help
node dist/index.js --help

Options

OptionDefaultDescription
--target-tokens <n>2000000Target output size in tokens. Small inputs are bloated up to this limit. Large inputs produce less bloat to stay within budget.
--help, -hShow help message

npm scripts

npm run build              # Compile TypeScript to dist/
npm run start              # Run the obfuscator (reads input.js)
npm run test               # Run the test suite
npm run obfuscate-package  # Run compatibility tests against npm packages

Programmatic API

const { obfuscate } = require('./dist/obfuscator');

const code = 'function add(a, b) { return a + b; }';
const obfuscated = obfuscate(code);

// With options
const obfuscated = obfuscate(code, { targetTokens: 500000 });

Transform Pipeline

The obfuscator applies 20 transforms across 4 phases. Each stage builds on the previous one.

Phase 1: Security & Anti-Analysis Pre-transforms

OrderTransformFileDescription
1Anti-Debug Trapstransforms/antiDebug.tsInjects eval("debugger") statements and 10-20 setInterval loops with prime-number intervals (5s-600s) that repeatedly trigger debugger breakpoints. Each instance uses unique encoded strings.
2Punctured Program Tripwirestransforms/tripwires.tsEmbeds hidden checks comparing parameter hashes against secret values. 5 hash patterns (bitwise fingerprint, modular arithmetic, charCodeAt, numeric hash, typeof+length). Triggers silent state corruption, busy loops, or throws on secret inputs. [Paper 4]
3LPN Noise Injectiontransforms/noiseInjection.tsAdds and cancels random noise through split paths in arithmetic computations. 6 patterns: add/sub, XOR, mul/div, split dual-variable, computed hash-chain, bit-rotate. Intermediate values are meaningless without tracing full cancellation. [Paper 7]

Phase 2: Structural Pre-transforms

OrderTransformFileDescription
4Control Flow Flatteningtransforms/controlFlowFlattening.tsConverts function bodies into while(true) { switch((_s * P) % M) { ... } } state machines with modular arithmetic dispatch — case values are encoded through (stateId * multiplier) % modulus using random prime parameters. [Paper 3]
5Opaque Predicatestransforms/opaquePredicates.tsInjects if conditions that always evaluate to true or false but are mathematically hard to prove (e.g., (x*x+x)%2===0). 15 predicate formulas across modular arithmetic, bitwise, and type-check categories.
6Proxy Functionstransforms/proxyFunctions.tsRoutes all function calls through two dispatchers: _fc(fn, ...args) for simple calls, _mc(obj, prop, ...args) for method calls. Uses Function.prototype.apply captured in a local variable for resilience.
7Context Window Exhaustiontransforms/contextExhaustion.tsWraps expressions in deeply nested ternaries with opaque conditions, void-expression chains, and conditional void padding. Forces LLMs to waste context window tokens on noise.
8Comma Expression Mergingtransforms/commaExpressions.tsCollapses consecutive expression statements into single comma expressions: a(); b(); return c() becomes return a(), b(), c().

Phase 3: Identifier Passes

OrderPassFileDescription
9Pass 1: Catalogpasses/firstPass.tsTraverses the AST and catalogs every identifier, building a globals map that assigns each a random 6-16 character Unicode name drawn from 16 script ranges (CJK, Hangul, Greek, Cyrillic, Devanagari, Thai, Arabic, Katakana, etc.).
10Pass 2: Substitutepasses/secondPass.tsReplaces all identifier names with their obfuscated Unicode equivalents. Encodes require() arguments as String.fromCharCode(...). Encodes static import/export sources as unicode-escaped string literals. Substitutes class superClass references, template literal expressions, destructuring patterns.
11Pass 3: Dummy Parameterspasses/thirdPass.tsInjects 0-15 random unused parameters into every function declaration and expression. Skips functions with rest parameters. Strips all comments.

Phase 4: Post-transforms

OrderTransformFileDescription
12Global Variable Encodingtransforms/globalVariableEncoding.tsReplaces references to globals (dynamically discovered from globalThis + window package) with eval("Name<suffix>".replace(new RegExp("<suffix>$"), "")). Both strings flow through the string array.
13Property Key Encodingtransforms/propertyKeyEncoding.tsConverts dot access to computed access with per-scope registries. Cross-scope access works because all suffixes resolve to the same property name at runtime via .replace().
14Number Encodingtransforms/numberEncoding.ts11 encoding strategies: shift+add, XOR identity, complement, division, nested shifts, double-NOT, modular, etc. Each instance uniquely generated. Skips property keys and switch case values.
15Self-Integrity Verificationtransforms/selfIntegrity.tsInjects 2-4 runtime checks: eval native-code verification, Function.prototype.toString integrity, timing anomaly detection, code structure validation. Anti-tamper responses: busy wait, throw, silent corruption. [Paper 10]
16String Array Extractiontransforms/stringArrayExtraction.tsCollects all strings into a single array with chained XOR decryption (key for entry N depends on decoded content of entry N-1) and sparse position-dependent error patterns (each character gets a different XOR key, with LPN-inspired sparse errors at select positions). [Papers 2, 9]
17Console Stubsobfuscator.tsDynamically discovers all console methods and sets each to a no-op function.
18Terser Minificationobfuscator.tsStrips whitespace/formatting via terser (mangle: false, compress: false). Falls back to regex-based stripping if terser can't parse the output.

Dead Code Injection

Dead code is injected at multiple points with two generation strategies:

Download Tool