@afterpack/core
v0.2.3
Published
JavaScript obfuscator engine for Node: protect your JavaScript source code in any build, locally or with AfterPack Pro
Maintainers
Readme
@afterpack/core
The engine behind AfterPack, the JavaScript obfuscator. It runs in Node, takes JavaScript and returns obfuscated JavaScript, so you can protect your JavaScript source code in any build.
Most people want the CLI (npx afterpack) or a framework plugin instead. Start with the quickstart or the CLI reference. Use this package when you are writing your own build step or tool.
Install
npm install @afterpack/coreNeeds Node 18 or later. The prebuilt binary for your platform installs with it.
Usage
import { obfuscate, obfuscateAll, version } from "@afterpack/core";
const result = await obfuscate('console.log("hello")', { preset: "hard" });
result.code; // the obfuscated source
result.bytes; // the same output as bytes, ready to write
// Several files at once. Results come back in input order.
const results = await obfuscateAll([
{ path: "dist/app.js", source: appSource },
{ path: "dist/vendor.js", source: vendorSource, sourceMap: vendorMap },
]);
await version(); // "0.1.0"obfuscate accepts a string, a Uint8Array, or a file object { path, source, sourceMap }, where sourceMap is the file's existing map to chain. Each result has code, bytes, sourceMap and diagnostics.
The second argument is the config: preset, complexity, sourceMap, identifiers, strings and more. Unknown keys are rejected, so a typo fails loudly. See the configuration reference.
Errors
If a build can't ship safely, the call throws. That covers an invalid config, a blocking diagnostic, or output that would go out unprotected. The error carries the engine's diagnostics:
import { obfuscate, ObfuscationError } from "@afterpack/core";
try {
await obfuscate(source);
} catch (err) {
if (err instanceof ObfuscationError) console.error(err.diagnostics);
throw err;
}Pro
Without a key, all of Free runs on your machine, with every preset, no account and no network call. Set your Pro key in the AFTERPACK_KEY environment variable (or pass key in the config) and the same call runs the build in AfterPack's cloud instead. Pro adds per-file and per-region direction through directives, stores each build's Protection Map, and shows your builds in the dashboard. It also offers two opt-in hardening settings, transforms.selfIntegrity and transforms.comparisonHardening, both off by default (details). It does not make any transform stronger. Read more about AfterPack Pro or see pricing.
Why this matters now: AI agents deobfuscate JavaScript that older tools protect. See how AfterPack compares to javascript-obfuscator and Jscrambler.
Platforms
- macOS: arm64 (Apple Silicon), x64
- Linux (glibc): x64, arm64
- Windows: x64
Alpine and other musl-based Linux have no native binary yet: use a glibc-based image. On those hosts, and anywhere a native addon can't load (such as a Cloudflare Worker), @afterpack/wasm runs the same obfuscate API.
License
Free for any use, including commercial and CI, with no limits, and the output is yours. You can't redistribute the binary on its own, build a competing obfuscation product or service on it, or reverse engineer it. See the AfterPack Engine License.
Questions and feedback: get in touch. Bug reports: GitHub.
