🚧 Work in progress - Initial tests seem to work but not validated and certainly not ready to use. Serverless mode also not working yet.
A high-performance Hybrid JavaScript Analysis Sandbox for detecting malicious behavior in untrusted code. JSNabber combines static analysis, dynamic execution, and function discovery to catch obfuscated malware that traditional scanners miss.
- Hybrid Analysis Engine:
- Static Analysis: Regex-based pattern detection for immediate risk flags (e.g.,
eval,document.cookie). - Dynamic Execution: Runs code in a secure QuickJS sandbox, logging all API calls (
fetch,atob,eval). - Function Discovery: Automatically finds and executes dormant functions that aren't called by the main script (e.g., hidden backdoors).
- Static Analysis: Regex-based pattern detection for immediate risk flags (e.g.,
- Web Interface: Clean, dark-mode UI for pasting code, uploading files, or fetching URLs.
- Robust Instrumentation:
- Stubs for Browser APIs (
window,document,navigator) - Stubs for Node.js APIs (
require,process,Buffer) - "Catch-all" Proxy for unknown global variables
- Stubs for Browser APIs (
- Portable Architecture: Core engine runs on both Native (Rust/Tokio) and Edge (WASM/Cloudflare Workers).
- Rust (latest stable)
Start the backend server and Web UI:
cargo run -p jsnabber-serverThen open http://localhost:3000 in your browser.
Verify the engine against included malware samples:
cargo test --package jsnabber-core- Technical Deep Dive: A comprehensive guide to the architecture, execution flow, and codebase.
- Malware Test Report: Analysis results from real world samples.
crates/jsnabber-core/: The heart of the engine. Contains the sandbox, instrumentation, and analysis logic.crates/jsnabber-server/: Axum-based web server that hosts the API and static UI.crates/jsnabber-worker/: Cloudflare Worker adapter for edge deployment.public/: Static web assets (HTML/CSS/JS) for the frontend.tests/malware-samples/: Real-world malware samples for verification.
- QuickJS provides isolation but is not a robust security boundary on its own.
- Always deploy with OS-level isolation (Docker containers, gVisor, or Cloudflare Workers isolates).
- Never run untrusted analysis on sensitive production infrastructure without proper sandboxing.
MIT / Apache-2.0