Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
esbuild-plugin-obfuscator
Advanced tools
An esbuild plugin that obfuscates JavaScript using javascript-obfuscator.
A plugin for esbuild that obfuscates JavaScript using javascript-obfuscator. This plugin allows developers to selectively obfuscate JavaScript files during the build process, enhancing security by making the code more difficult to read and understand.
Install the plugin with npm:
npm install esbuild-obfuscator-plugin --save-dev
To use the esbuild-obfuscator-plugin
, import it in your build script and configure it according to your needs. Below is an example of how to set up the plugin with esbuild
:
import esbuild from 'esbuild';
import { ObfuscatorPlugin } from 'esbuild-obfuscator-plugin';
// Run esbuild with the obfuscator plugin and micromatch file filtering
esbuild.build({
entryPoints: ['src/main.js'], // Entry files to build
bundle: true,
outfile: 'dist/output.js', // Output file
plugins: [
ObfuscatorPlugin({
compact: true, // Obfuscator options
controlFlowFlattening: true,
filter: ['**/sanitize.js'], // Obfuscate 'sanitize.js' only
}),
],
}).then(() => {
console.log('Build complete with selective obfuscation');
}).catch(() => process.exit(1));
The ObfuscatorPlugin
accepts the following options:
filter (Array<string>
): A list of micromatch patterns that specify which files should be obfuscated. Default is an empty array []
.
shouldObfuscateOutput (boolean
): If set to true
, the plugin will obfuscate all output files after the build process is completed. Default is false
.
ignoreRequireImports (boolean
): If set to true
, it prevents obfuscation of require
imports. Could be helpful in some cases when for some reason runtime environment requires these imports with static strings only.
options (Object
): Additional options for the javascript-obfuscator
. This can include various configurations available in javascript-obfuscator.
You can also configure the plugin to obfuscate the output files as follows:
esbuild.build({
entryPoints: ['src/main.js'],
bundle: true,
outfile: 'dist/output.js',
plugins: [
ObfuscatorPlugin({
shouldObfuscateOutput: true, // Obfuscate all output files
compact: true,
controlFlowFlattening: true,
}),
],
}).then(() => {
console.log('Build complete with output obfuscation');
}).catch(() => process.exit(1));
The plugin uses micromatch to filter which files are obfuscated. You can use patterns like:
**/*.js
to match all JavaScript files.**/folder/*.js
to match JavaScript files in a specific folder.!**/exclude/**
to exclude files from being obfuscated.ObfuscatorPlugin({
filter: ['**/*.js', '!**/exclude/**'],
});
Contributions are welcome! If you would like to contribute to this project, please fork the repository and submit a pull request. Ensure that your code follows the project's style and is well-documented.
This project is licensed under the MIT License.
If you encounter any issues or have questions, feel free to open an issue on the GitHub repository.
FAQs
An esbuild plugin that obfuscates JavaScript using javascript-obfuscator.
The npm package esbuild-plugin-obfuscator receives a total of 13 weekly downloads. As such, esbuild-plugin-obfuscator popularity was classified as not popular.
We found that esbuild-plugin-obfuscator demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.