
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
esbuild-plugin-obfuscator
Advanced tools
An esbuild plugin that obfuscates JavaScript using javascript-obfuscator.
A plugin for esbuild that obfuscates JavaScript using javascript-obfuscator. This plugin allows developers to selectively obfuscate JavaScript files during the build process, enhancing security by making the code more difficult to read and understand.
Install the plugin with npm:
npm install esbuild-plugin-obfuscator --save-dev
To use the esbuild-plugin-obfuscator, import it in your build script and configure it according to your needs. Below is an example of how to set up the plugin with esbuild:
import esbuild from 'esbuild';
import { ObfuscatorPlugin } from 'esbuild-plugin-obfuscator';
// Run esbuild with the obfuscator plugin and micromatch file filtering
esbuild.build({
entryPoints: ['src/main.js'], // Entry files to build
bundle: true,
outfile: 'dist/output.js', // Output file
plugins: [
ObfuscatorPlugin({
compact: true, // Obfuscator options
controlFlowFlattening: true,
filter: ['**/sanitize.js'], // Obfuscate 'sanitize.js' only
}),
],
}).then(() => {
console.log('Build complete with selective obfuscation');
}).catch(() => process.exit(1));
The ObfuscatorPlugin accepts the following options:
filter (Array<string>): A list of micromatch patterns that specify which files should be obfuscated. Default is an empty array [].
shouldObfuscateOutput (boolean): If set to true, the plugin will obfuscate all output files after the build process is completed. Default is false.
shouldWriteOutputSourceMap (boolean): If set to true, writes the output source map files when obfuscating the final output. This option is only relevant if shouldObfuscateOutput is true. Default is false.
ignoreRequireImports (boolean): If set to true, it prevents obfuscation of require imports. Could be helpful in some cases when for some reason runtime environment requires these imports with static strings only.
options (Object): Additional options for the javascript-obfuscator. This can include various configurations available in javascript-obfuscator.
The plugin automatically generates source maps for obfuscated code to help with debugging:
shouldObfuscateOutput: true, you can enable shouldWriteOutputSourceMap: true to write separate .map files alongside the obfuscated output files.You can also configure the plugin to obfuscate the output files with source map generation:
esbuild.build({
entryPoints: ['src/main.js'],
bundle: true,
outfile: 'dist/output.js',
sourcemap: true, // Enable esbuild source maps
plugins: [
ObfuscatorPlugin({
shouldObfuscateOutput: true, // Obfuscate all output files
shouldWriteOutputSourceMap: true, // Generate .map files for obfuscated output
compact: true,
controlFlowFlattening: true,
}),
],
}).then(() => {
console.log('Build complete with output obfuscation and source maps');
}).catch(() => process.exit(1));
For transform-time obfuscation, source maps are automatically integrated into esbuild's source map chain:
esbuild.build({
entryPoints: ['src/main.js'],
bundle: true,
outfile: 'dist/output.js',
sourcemap: true, // Enable esbuild source maps
plugins: [
ObfuscatorPlugin({
filter: ['**/sanitize.js'], // Obfuscate specific files
compact: true,
controlFlowFlattening: true,
}),
],
}).then(() => {
console.log('Build complete with selective obfuscation and integrated source maps');
}).catch(() => process.exit(1));
The plugin uses micromatch to filter which files are obfuscated. You can use patterns like:
**/*.js to match all JavaScript files.**/folder/*.js to match JavaScript files in a specific folder.!**/exclude/** to exclude files from being obfuscated.ObfuscatorPlugin({
filter: ['**/*.js', '!**/exclude/**'],
});
Contributions are welcome! If you would like to contribute to this project, please fork the repository and submit a pull request. Ensure that your code follows the project's style and is well-documented.
This project is licensed under the MIT License.
onTransform and onEnd hooks.If you encounter any issues or have questions, feel free to open an issue on the GitHub repository.
FAQs
An esbuild plugin that obfuscates JavaScript using javascript-obfuscator.
The npm package esbuild-plugin-obfuscator receives a total of 694 weekly downloads. As such, esbuild-plugin-obfuscator popularity was classified as not popular.
We found that esbuild-plugin-obfuscator demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.