JavaScriptObfuscator.ts 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302
  1. import { inject, injectable, } from 'inversify';
  2. import { ServiceIdentifiers } from './container/ServiceIdentifiers';
  3. import * as esprima from 'esprima';
  4. import * as escodegen from 'escodegen-wallaby';
  5. import * as ESTree from 'estree';
  6. import * as packageJson from 'pjson';
  7. import { ICustomNodeGroup } from './interfaces/custom-nodes/ICustomNodeGroup';
  8. import { IGeneratorOutput } from './interfaces/IGeneratorOutput';
  9. import { IJavaScriptObfuscator } from './interfaces/IJavaScriptObfsucator';
  10. import { ILogger } from './interfaces/logger/ILogger';
  11. import { IObfuscationEventEmitter } from './interfaces/event-emitters/IObfuscationEventEmitter';
  12. import { IObfuscationResult } from './interfaces/IObfuscationResult';
  13. import { IOptions } from './interfaces/options/IOptions';
  14. import { IRandomGenerator } from './interfaces/utils/IRandomGenerator';
  15. import { ISourceMapCorrector } from './interfaces/source-map/ISourceMapCorrector';
  16. import { IStackTraceAnalyzer } from './interfaces/analyzers/stack-trace-analyzer/IStackTraceAnalyzer';
  17. import { IStackTraceData } from './interfaces/analyzers/stack-trace-analyzer/IStackTraceData';
  18. import { IStorage } from './interfaces/storages/IStorage';
  19. import { ITransformersRunner } from './interfaces/node-transformers/ITransformersRunner';
  20. import { LoggingMessage } from './enums/logger/LoggingMessage';
  21. import { NodeTransformer } from './enums/node-transformers/NodeTransformer';
  22. import { ObfuscationEvent } from './enums/event-emitters/ObfuscationEvent';
  23. import { NodeGuards } from './node/NodeGuards';
  24. @injectable()
  25. export class JavaScriptObfuscator implements IJavaScriptObfuscator {
  26. /**
  27. * @type {GenerateOptions}
  28. */
  29. private static readonly escodegenParams: escodegen.GenerateOptions = {
  30. comment: true,
  31. verbatim: 'x-verbatim-property',
  32. sourceMapWithCode: true
  33. };
  34. /**
  35. * @type {NodeTransformer[]}
  36. */
  37. private static readonly controlFlowTransformersList: NodeTransformer[] = [
  38. NodeTransformer.BlockStatementControlFlowTransformer,
  39. NodeTransformer.FunctionControlFlowTransformer
  40. ];
  41. /**
  42. * @type {NodeTransformer[]}
  43. */
  44. private static readonly convertingTransformersList: NodeTransformer[] = [
  45. NodeTransformer.MemberExpressionTransformer,
  46. NodeTransformer.MethodDefinitionTransformer,
  47. NodeTransformer.TemplateLiteralTransformer
  48. ];
  49. /**
  50. * @type {NodeTransformer[]}
  51. */
  52. private static readonly deadCodeInjectionTransformersList: NodeTransformer[] = [
  53. NodeTransformer.DeadCodeInjectionTransformer
  54. ];
  55. /**
  56. * @type {NodeTransformer[]}
  57. */
  58. private static readonly obfuscatingTransformersList: NodeTransformer[] = [
  59. NodeTransformer.CatchClauseTransformer,
  60. NodeTransformer.ClassDeclarationTransformer,
  61. NodeTransformer.FunctionDeclarationTransformer,
  62. NodeTransformer.FunctionTransformer,
  63. NodeTransformer.LabeledStatementTransformer,
  64. NodeTransformer.LiteralTransformer,
  65. NodeTransformer.ObjectExpressionTransformer,
  66. NodeTransformer.VariableDeclarationTransformer
  67. ];
  68. /**
  69. * @type {NodeTransformer[]}
  70. */
  71. private static readonly preparingTransformersList: NodeTransformer[] = [
  72. NodeTransformer.CommentsTransformer,
  73. NodeTransformer.ObfuscatingGuardsTransformer,
  74. NodeTransformer.ParentificationTransformer
  75. ];
  76. /**
  77. * @type {IStorage<ICustomNodeGroup>}
  78. */
  79. private readonly customNodeGroupStorage: IStorage<ICustomNodeGroup>;
  80. /**
  81. * @type {ILogger}
  82. */
  83. private readonly logger: ILogger;
  84. /**
  85. * @type {IObfuscationEventEmitter}
  86. */
  87. private readonly obfuscationEventEmitter: IObfuscationEventEmitter;
  88. /**
  89. * @type {IOptions}
  90. */
  91. private readonly options: IOptions;
  92. /**
  93. * @type {IRandomGenerator}
  94. */
  95. private readonly randomGenerator: IRandomGenerator;
  96. /**
  97. * @type {ISourceMapCorrector}
  98. */
  99. private readonly sourceMapCorrector: ISourceMapCorrector;
  100. /**
  101. * @type {IStackTraceAnalyzer}
  102. */
  103. private readonly stackTraceAnalyzer: IStackTraceAnalyzer;
  104. /**
  105. * @type {ITransformersRunner}
  106. */
  107. private readonly transformersRunner: ITransformersRunner;
  108. /**
  109. * @param {IStackTraceAnalyzer} stackTraceAnalyzer
  110. * @param {IObfuscationEventEmitter} obfuscationEventEmitter
  111. * @param {IStorage<ICustomNodeGroup>} customNodeGroupStorage
  112. * @param {ITransformersRunner} transformersRunner
  113. * @param {ISourceMapCorrector} sourceMapCorrector
  114. * @param {IRandomGenerator} randomGenerator
  115. * @param {ILogger} logger
  116. * @param {IOptions} options
  117. */
  118. constructor (
  119. @inject(ServiceIdentifiers.IStackTraceAnalyzer) stackTraceAnalyzer: IStackTraceAnalyzer,
  120. @inject(ServiceIdentifiers.IObfuscationEventEmitter) obfuscationEventEmitter: IObfuscationEventEmitter,
  121. @inject(ServiceIdentifiers.TCustomNodeGroupStorage) customNodeGroupStorage: IStorage<ICustomNodeGroup>,
  122. @inject(ServiceIdentifiers.ITransformersRunner) transformersRunner: ITransformersRunner,
  123. @inject(ServiceIdentifiers.ISourceMapCorrector) sourceMapCorrector: ISourceMapCorrector,
  124. @inject(ServiceIdentifiers.IRandomGenerator) randomGenerator: IRandomGenerator,
  125. @inject(ServiceIdentifiers.ILogger) logger: ILogger,
  126. @inject(ServiceIdentifiers.IOptions) options: IOptions
  127. ) {
  128. this.stackTraceAnalyzer = stackTraceAnalyzer;
  129. this.obfuscationEventEmitter = obfuscationEventEmitter;
  130. this.customNodeGroupStorage = customNodeGroupStorage;
  131. this.transformersRunner = transformersRunner;
  132. this.sourceMapCorrector = sourceMapCorrector;
  133. this.randomGenerator = randomGenerator;
  134. this.logger = logger;
  135. this.options = options;
  136. }
  137. /**
  138. * @param {string} sourceCode
  139. * @returns {IObfuscationResult}
  140. */
  141. public obfuscate (sourceCode: string): IObfuscationResult {
  142. const timeStart: number = Date.now();
  143. this.logger.info(LoggingMessage.Version, packageJson.version);
  144. this.logger.info(LoggingMessage.ObfuscationStarted);
  145. this.logger.info(LoggingMessage.RandomGeneratorSeed, this.randomGenerator.getSeed());
  146. // parse AST tree
  147. const astTree: ESTree.Program = this.parseCode(sourceCode);
  148. // obfuscate AST tree
  149. const obfuscatedAstTree: ESTree.Program = this.transformAstTree(astTree);
  150. // generate code
  151. const generatorOutput: IGeneratorOutput = this.generateCode(sourceCode, obfuscatedAstTree);
  152. const obfuscationTime: number = (Date.now() - timeStart) / 1000;
  153. this.logger.success(LoggingMessage.ObfuscationCompleted, obfuscationTime);
  154. return this.getObfuscationResult(generatorOutput);
  155. }
  156. /**
  157. * @param {string} sourceCode
  158. * @returns {Program}
  159. */
  160. private parseCode (sourceCode: string): ESTree.Program {
  161. return esprima.parseScript(sourceCode, {
  162. attachComment: true,
  163. loc: this.options.sourceMap
  164. });
  165. }
  166. /**
  167. * @param {Program} astTree
  168. * @returns {Program}
  169. */
  170. private transformAstTree (astTree: ESTree.Program): ESTree.Program {
  171. const isEmptyAstTree: boolean = NodeGuards.isProgramNode(astTree)
  172. && !astTree.body.length
  173. && !astTree.leadingComments;
  174. if (isEmptyAstTree) {
  175. this.logger.warn(LoggingMessage.EmptySourceCode);
  176. return astTree;
  177. }
  178. // first pass: AST-tree preparation
  179. this.logger.info(LoggingMessage.StagePreparingASTTree);
  180. astTree = this.transformersRunner.transform(
  181. astTree,
  182. JavaScriptObfuscator.preparingTransformersList
  183. );
  184. // second pass: AST-tree analyzing
  185. this.logger.info(LoggingMessage.StageAnalyzingASTTree);
  186. const stackTraceData: IStackTraceData[] = this.stackTraceAnalyzer.analyze(astTree);
  187. // initialize custom node groups and configure custom nodes
  188. this.customNodeGroupStorage
  189. .getStorage()
  190. .forEach((customNodeGroup: ICustomNodeGroup) => {
  191. customNodeGroup.initialize();
  192. this.obfuscationEventEmitter.once(
  193. customNodeGroup.getAppendEvent(),
  194. customNodeGroup.appendCustomNodes.bind(customNodeGroup)
  195. );
  196. });
  197. this.obfuscationEventEmitter.emit(ObfuscationEvent.BeforeObfuscation, astTree, stackTraceData);
  198. // third pass: dead code injection transformer
  199. if (this.options.deadCodeInjection) {
  200. this.logger.info(LoggingMessage.StageDeadCodeInjection);
  201. astTree = this.transformersRunner.transform(
  202. astTree,
  203. JavaScriptObfuscator.deadCodeInjectionTransformersList
  204. );
  205. }
  206. // fourth pass: control flow flattening transformers
  207. if (this.options.controlFlowFlattening) {
  208. this.logger.info(LoggingMessage.StageControlFlowFlattening);
  209. astTree = this.transformersRunner.transform(
  210. astTree,
  211. JavaScriptObfuscator.controlFlowTransformersList
  212. );
  213. }
  214. // fifth pass: converting and obfuscating transformers
  215. this.logger.info(LoggingMessage.StageObfuscation);
  216. astTree = this.transformersRunner.transform(astTree, [
  217. ...JavaScriptObfuscator.convertingTransformersList,
  218. ...JavaScriptObfuscator.obfuscatingTransformersList
  219. ]);
  220. this.obfuscationEventEmitter.emit(ObfuscationEvent.AfterObfuscation, astTree, stackTraceData);
  221. return astTree;
  222. }
  223. /**
  224. * @param {string} sourceCode
  225. * @param {Program} astTree
  226. * @returns {IGeneratorOutput}
  227. */
  228. private generateCode (sourceCode: string, astTree: ESTree.Program): IGeneratorOutput {
  229. const escodegenParams: escodegen.GenerateOptions = {
  230. ...JavaScriptObfuscator.escodegenParams
  231. };
  232. if (this.options.sourceMap) {
  233. escodegenParams.sourceMap = 'sourceMap';
  234. escodegenParams.sourceContent = sourceCode;
  235. }
  236. const generatorOutput: IGeneratorOutput = escodegen.generate(astTree, {
  237. ...escodegenParams,
  238. format: {
  239. compact: this.options.compact
  240. }
  241. });
  242. generatorOutput.map = generatorOutput.map ? generatorOutput.map.toString() : '';
  243. return generatorOutput;
  244. }
  245. /**
  246. * @param {IGeneratorOutput} generatorOutput
  247. * @returns {IObfuscationResult}
  248. */
  249. private getObfuscationResult (generatorOutput: IGeneratorOutput): IObfuscationResult {
  250. return this.sourceMapCorrector.correct(
  251. generatorOutput.code,
  252. generatorOutput.map
  253. );
  254. }
  255. }