キツネ · Kitsune Labs

Kitsune JavaScript Obfuscator

A source-to-source obfuscator built on the Babel AST. Control-flow flattening, XOR string encryption, bytecode-style output, self-defending checks and domain lock, tuned for Google Apps Script without breaking doGet orSpreadsheetApp.

「狐に化かされる」 — to be bewitched by the fox. It looks strange. It runs the same.

Try it — 変換する

A browser lite edition of Kitsune's XOR string-encryption and arithmetic modes, running entirely on this page. Nothing is uploaded. The full CLI adds control-flow flattening, dead code, homoglyph renaming and more.

// the fox awaits your code…

Template literals are passed through unencrypted. Output is demo-grade: for production strength (and GAS-safe reserved-name handling) use the CLI.

The full pipeline — 六つの道

XOR string encryption

Every literal becomes a call to an injected decoder over encrypted byte arrays. A strings dump shows nothing.

Arithmetic encoding

Numeric constants become expressions. 5005 becomes 3899+1106. Defeats constant scanning.

Control-flow flattening

Straight-line code becomes a state-machine dispatch loop. Reading top-to-bottom reveals nothing.

Bytecode look

Hex-style identifiers and compact emission that resembles compiled artifacts more than source.

Self-defending + domain lock

Anti-tamper runtime checks and license pinning to a domain or GAS Script ID.

Performance mode

--perf trades flattening for homoglyph renaming and string splitting. Fast, subtle, deploy-safe.

🦊 Read how it was built

The design story is in the blog: why regex obfuscators break real code, and how Google Apps Script's reserved entry points shaped every pass.

building kitsune →