Skip to content

Named Methods, CFF/js-confuser Processors, and Sandbox Hardening - #8

Merged
ctrl-escp merged 12 commits into
mainfrom
dev
Aug 30, 2026
Merged

ctrl-escp merged 12 commits into
mainfrom
dev

Conversation

@ctrl-escp

@ctrl-escp ctrl-escp commented Aug 30, 2026 •

Copy link
Copy Markdown
Owner

Features

  • --method / -M to run named deobfuscation methods in a chosen order (skips pre/postprocessors unless opted in)
  • --skip-preprocessors, --run-preproc, --run-postproc, and --no-detect for targeted runs
  • --max-marked-nodes to cap marks per method, and --safely to keep valid edits when one queued change would fail
  • CFF flattening processor for cff_storage_object and sequenced_index_switch
  • js-confuser processors for string-bank indexer calls and state machines
  • flattenStringArrayDecoder preprocessor for string-array decoder factories and aliases
  • New safe modules: inlineOperatorObjects, resolveDeterministicWhileStatements, resolveNestedBinaryExpressions, resolvePureLiteralMethodCalls

Safety

  • Neutralize injected strings and nodes before they land in the AST
  • Hide host bindings and block Node / Deno / Bun APIs in the sandbox
  • Inert BOM stubs so guest code cannot poke browser globals

Fixes

  • Fold remapped literal binaries and decoder aliases more reliably
  • Include replaceArrayWithStaticAugmentedVersion in function-to-array preprocessing
  • Strengthen obfuscator.io processing and switch rearrangement
  • Move normalizeRedundantNotOperator, resolveDefiniteMemberExpressions, resolveDeterministicConditionalExpressions, and resolveMinimalAlphabet from unsafe to safe

Dependencies

  • Upgrade flast to 3.2.0 and obfuscation-detector to 3.1.1
  • Upgrade commander to 15 and js-md5 to 0.9.2
  • Allow isolated-vm peer ^6.2.0 || ^7.0.1
  • Add Node 26.x to CI

- Upgrade 'commander' to version 15.0.0, 'flast' to version 3.1.0, 'js-md5' to version 0.9.2, and 'obfuscation-detector' to version 3.0.1 for improved functionality and security.
- Update 'eslint' to version 10.9.1 and 'globals' to version 17.11.0 in devDependencies.
- Adjust 'isolated-vm' peer dependency to support versions 6.2.0 and 7.0.1.
- Modify GitHub Actions workflow to include Node.js version 26.x for CI compatibility.
- Introduced a new module for resolving nested binary expressions, enhancing the evaluation of mixed arithmetic and string operations.
- Updated the safe module index to include the new resolveNestedBinaryExpressions function.
- Added comprehensive tests to validate the functionality of nested binary expression resolution, covering various arithmetic and concatenation scenarios.
…nd deterministic conditional expressions

- Added `normalizeRedundantNotOperator` to optimize the evaluation of NOT expressions on literals, improving code readability and performance.
- Introduced `resolveDeterministicConditionalExpressions` to resolve ternary expressions with literal test values, enhancing the evaluation of conditional logic.
- Updated the safe module index to include the new functions and added corresponding tests to validate their functionality.
- Refactored existing modules to ensure compatibility and improved organization of utility functions for truthiness evaluation.
…odes

- Introduced `neutralizeInjectedString` and `neutralizeInjectedNode` functions to replace unsafe strings and identifiers in AST nodes, improving security against injection attacks.
- Updated multiple modules to utilize these new functions, ensuring that identifiers and literal values are sanitized before being processed.
- Added comprehensive tests to validate the functionality of the neutralization process, covering various scenarios including debugger identifiers.
- Refactored existing utility functions to integrate the new neutralization logic, enhancing overall code safety and maintainability.
…odes

- Introduced `neutralizeInjectedString` and `neutralizeInjectedNode` functions to replace unsafe strings and identifiers in AST nodes, improving security against injection attacks.
- Updated multiple modules to utilize these new functions, ensuring that identifiers and literal values are sanitized before being processed.
- Added comprehensive tests to validate the functionality of the neutralization process, covering various scenarios including debugger identifiers.
- Refactored existing utility functions to integrate the new neutralization logic, enhancing overall code safety and maintainability.
- Directed `npm test` tests to run against all test files in the tests/ directory.
- Introduced a comprehensive approach to hide host bindings and block access to Node, Deno, and Bun APIs, ensuring guest code cannot access sensitive environment details.
- Implemented inert BOM stubs for browser-related objects, allowing for safer execution of guest code while maintaining necessary functionality.
- Refactored the sandbox provider to utilize new hardening sources, improving isolation during execution.
- Updated tests to validate the effectiveness of the new sandboxing measures, ensuring blocked APIs behave as expected and do not leak host information.
- Enhanced documentation to clarify the purpose and functionality of the new sandbox features.
…atement resolution

- Introduced `inlineOperatorObjects` to enhance the handling of operator objects in the AST, improving code transformation capabilities.
- Added `resolveDeterministicWhileStatements` to identify and resolve while loops with deterministic test conditions, complementing existing conditional resolution features.
- Updated the safe module index to include the new functions and added corresponding tests to validate their functionality.
- Enhanced existing modules to integrate new resolution logic for improved performance and maintainability.
…ctions

- Introduced `literalNumber` and `foldRemappedLiteralBinary` functions to improve the handling of numeric literals in binary expressions.
- Updated `remapArg` to utilize the new folding logic, enhancing the transformation of arguments in function calls.
- Added `flattenStringArrayDecoder` to preprocessors in multiple modules, improving the handling of string arrays and decoder calls.
- Enhanced tests to cover new functionality, including flattening factory calls and handling decoder aliases.
- Refactored existing code for better organization and maintainability.
- Upgraded `obfuscation-detector` to version 3.1.0 in both package.json and package-lock.json for improved functionality.
- Modified the `preprocessors` array in `functionToArray.js` to include `replaceArrayWithStaticAugmentedVersion`, enhancing the processing capabilities.
- Updated the test case in `deobfuscation.test.js` to reflect changes in expected output for augmented function replacements.
- Introduced `cffFlattening.js` to handle control-flow flattening for `cff_storage_object` and `sequenced_index_switch`, enhancing code obfuscation capabilities.
- Added `jsConfuser.js` for processing string bank indexer calls and state machines, improving the handling of complex function calls.
- Updated `index.js` to include new processors and ensure proper integration.
- Implemented comprehensive tests for both processors, validating their functionality and ensuring expected transformations in various scenarios.
- Upgraded `flast` to version 3.2.0 and `obfuscation-detector` to version 3.1.1 in both package.json and package-lock.json for enhanced functionality and performance.
…processing logic

- Added support for named deobfuscation methods via the `--method` option, allowing users to specify methods in order.
- Introduced options to skip preprocessors and run specific preprocessors or postprocessors when using named methods.
- Implemented `maxMarkedNodes` to limit the number of marked nodes during deobfuscation, enhancing control over the process.
- Added `safely` option to apply valid edits while ignoring failures in queued changes.
- Updated the `REstringer` class and related modules to accommodate new options and improve processing logic.
- Enhanced documentation and tests to cover new features and ensure expected behavior.
@ctrl-escp

Copy link
Copy Markdown
Owner Author

Opened by mistake — you asked for title/body text only.

@ctrl-escp ctrl-escp closed this Aug 30, 2026
@ctrl-escp ctrl-escp reopened this Aug 30, 2026
@ctrl-escp ctrl-escp self-assigned this Aug 30, 2026
@ctrl-escp ctrl-escp added the enhancement New feature or request label Aug 30, 2026
@ctrl-escp
ctrl-escp merged commit e94f445 into main Aug 30, 2026
8 of 9 checks passed
@ctrl-escp
ctrl-escp deleted the dev branch August 30, 2026 21:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant