Skip to content
aesraelPublic

About

[WIP] - A high-performance JavaScript dynamic analysis sandbox for detecting malicious behavior in untrusted code.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

5 Commits

Folders and files

Repository files navigation

JSNabber

🚧 Work in progress - Initial tests seem to work but not validated and certainly not ready to use. Serverless mode also not working yet.

A high-performance Hybrid JavaScript Analysis Sandbox for detecting malicious behavior in untrusted code. JSNabber combines static analysis, dynamic execution, and function discovery to catch obfuscated malware that traditional scanners miss.

🎯 Features

  • Hybrid Analysis Engine:
    • Static Analysis: Regex-based pattern detection for immediate risk flags (e.g., eval, document.cookie).
    • Dynamic Execution: Runs code in a secure QuickJS sandbox, logging all API calls (fetch, atob, eval).
    • Function Discovery: Automatically finds and executes dormant functions that aren't called by the main script (e.g., hidden backdoors).
  • Web Interface: Clean, dark-mode UI for pasting code, uploading files, or fetching URLs.
  • Robust Instrumentation:
    • Stubs for Browser APIs (window, document, navigator)
    • Stubs for Node.js APIs (require, process, Buffer)
    • "Catch-all" Proxy for unknown global variables
  • Portable Architecture: Core engine runs on both Native (Rust/Tokio) and Edge (WASM/Cloudflare Workers).

🚀 Quick Start

Prerequisites

  • Rust (latest stable)

Running the Server

Start the backend server and Web UI:

cargo run -p jsnabber-server

Then open http://localhost:3000 in your browser.

Running Tests

Verify the engine against included malware samples:

cargo test --package jsnabber-core

📚 Documentation

🏗️ Project Structure

  • crates/jsnabber-core/: The heart of the engine. Contains the sandbox, instrumentation, and analysis logic.
  • crates/jsnabber-server/: Axum-based web server that hosts the API and static UI.
  • crates/jsnabber-worker/: Cloudflare Worker adapter for edge deployment.
  • public/: Static web assets (HTML/CSS/JS) for the frontend.
  • tests/malware-samples/: Real-world malware samples for verification.

🛡️ Security Model

⚠️ JSNabber assumes all analyzed code is hostile.

  • QuickJS provides isolation but is not a robust security boundary on its own.
  • Always deploy with OS-level isolation (Docker containers, gVisor, or Cloudflare Workers isolates).
  • Never run untrusted analysis on sensitive production infrastructure without proper sandboxing.

License

MIT / Apache-2.0

About

[WIP] - A high-performance JavaScript dynamic analysis sandbox for detecting malicious behavior in untrusted code.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages