npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@afterpack/core

v0.2.3

Published

JavaScript obfuscator engine for Node: protect your JavaScript source code in any build, locally or with AfterPack Pro

Readme

@afterpack/core

The engine behind AfterPack, the JavaScript obfuscator. It runs in Node, takes JavaScript and returns obfuscated JavaScript, so you can protect your JavaScript source code in any build.

Most people want the CLI (npx afterpack) or a framework plugin instead. Start with the quickstart or the CLI reference. Use this package when you are writing your own build step or tool.

Install

npm install @afterpack/core

Needs Node 18 or later. The prebuilt binary for your platform installs with it.

Usage

import { obfuscate, obfuscateAll, version } from "@afterpack/core";

const result = await obfuscate('console.log("hello")', { preset: "hard" });
result.code;  // the obfuscated source
result.bytes; // the same output as bytes, ready to write

// Several files at once. Results come back in input order.
const results = await obfuscateAll([
  { path: "dist/app.js", source: appSource },
  { path: "dist/vendor.js", source: vendorSource, sourceMap: vendorMap },
]);

await version(); // "0.1.0"

obfuscate accepts a string, a Uint8Array, or a file object { path, source, sourceMap }, where sourceMap is the file's existing map to chain. Each result has code, bytes, sourceMap and diagnostics.

The second argument is the config: preset, complexity, sourceMap, identifiers, strings and more. Unknown keys are rejected, so a typo fails loudly. See the configuration reference.

Errors

If a build can't ship safely, the call throws. That covers an invalid config, a blocking diagnostic, or output that would go out unprotected. The error carries the engine's diagnostics:

import { obfuscate, ObfuscationError } from "@afterpack/core";

try {
  await obfuscate(source);
} catch (err) {
  if (err instanceof ObfuscationError) console.error(err.diagnostics);
  throw err;
}

Pro

Without a key, all of Free runs on your machine, with every preset, no account and no network call. Set your Pro key in the AFTERPACK_KEY environment variable (or pass key in the config) and the same call runs the build in AfterPack's cloud instead. Pro adds per-file and per-region direction through directives, stores each build's Protection Map, and shows your builds in the dashboard. It also offers two opt-in hardening settings, transforms.selfIntegrity and transforms.comparisonHardening, both off by default (details). It does not make any transform stronger. Read more about AfterPack Pro or see pricing.

Why this matters now: AI agents deobfuscate JavaScript that older tools protect. See how AfterPack compares to javascript-obfuscator and Jscrambler.

Platforms

  • macOS: arm64 (Apple Silicon), x64
  • Linux (glibc): x64, arm64
  • Windows: x64

Alpine and other musl-based Linux have no native binary yet: use a glibc-based image. On those hosts, and anywhere a native addon can't load (such as a Cloudflare Worker), @afterpack/wasm runs the same obfuscate API.

License

Free for any use, including commercial and CI, with no limits, and the output is yours. You can't redistribute the binary on its own, build a competing obfuscation product or service on it, or reverse engineer it. See the AfterPack Engine License.

Questions and feedback: get in touch. Bug reports: GitHub.