Skip to content
Conference Open access

Static Code Analysis Output as a Proxy Indicator for Classifying JavaScript Obfuscation

2026 · International Conference on Security and Cryptography · pp. 1073-1080 · 0 citations · 22 references
Computer Science

TL;DR

It is demonstrated that SCA warnings deviate under obfuscation and provide a practical proxy indicator for distinguishing obfuscated code from human-readable code.

Abstract

: This study investigates whether the output of Static Code Analysis (SCA) tools can serve as a proxy indicator for identifying obfuscated JavaScript. Two datasets are analyzed in their original and obfuscated forms: a controlled pilot dataset focused on common malicious patterns and a larger Kaggle dataset of approximately 1900 real-world JavaScript files. Four SCA tools are applied to both datasets: SonarQube, ESLint, NodeJsScan, and JSHint. The outputs are normalized into a unified feature schema, and pre/post-obfuscation deviance is quantified through issue counts and Kernel Density Estimation (KDE) of warnings normalized by file size and line count. Results show large and consistent increases in issue counts for ESLint and JSHint, substantial rises for SonarQube, and unstable shifts for NodeJsScan. The KDE analysis strengthens the proxy indicator’s effectiveness beyond raw counts by confirming that normalized warning intensity rises after obfuscation for SonarQube and JSHint. These patterns demonstrate that SCA warnings deviate under obfuscation and provide a practical proxy indicator for distinguishing obfuscated code from human-readable code.

Read PDF

Similar papers

Open access Sep 2026

JSCoherence: detecting obfuscated malicious JavaScript via data-dependent statement pairs

As a crucial component of websites, JavaScript is one of the most common attack payloads on malicious websites. Although many methods for detecting malicious JavaScript have been proposed, obfuscation techniques make it difficult for previous approaches to detect disguised malicious JavaScript effectively. To address t...

Zi-Xian Chen, Weiping Wang, Ze-Song Gu et al. · 0 citations
Preprint Sep 2026

CASHEWS: Source Preprocessor for LLM-based Malicious Package Detection

Malicious npm package detection tools now leverage LLMs'semantic understanding of source code to detect malicious intent at scale. This capability has proven invaluable in identifying packages involved in recent supply-chain attacks such as Shai-Hulud. However, threat actors exploit the limited context windows of LLMs...

Jean-Charles Noirot Ferrand, David Adei, Anders Møller et al. · 0 citations
#small language model Book Oct 2026

Defensive Capability Analysis for JavaScript Libraries

A defensive capability analysis for JavaScript libraries that soundly reports every exercised capability for code executed under a lightweight protected runtime, complementing the static analysis with a lightweight runtime enforcement mechanism that blocks those patterns.

Wen-Yu Xu, Anders Møller · 0 citations

Defensive Capability Analysis for JavaScript Libraries

A defensive capability analysis for JavaScript libraries that soundly reports every exercised capability for code executed under a lightweight protected runtime, complementing the static analysis with a lightweight runtime enforcement mechanism that blocks those patterns.

Unknown authors · 1 citation
#small language model Preprint Sep 2026

Towards Behavior Tree-Guided Vulnerability Detection with Lightweight LLMs

Investigating Behavior Trees (BTs) as an alternative intermediate representation for LLM-based vulnerability detection suggests that BTs can provide a compact and useful structured representation for vulnerability detection with quantized, locally deployable LLMs.

Enna Bašić, A. Giaretta · 0 citations
Preprint Aug 2026

Beyond Source: An Empirical Study of Python Bytecode Security Risks

Python package security is largely source-centric, yet Python runtimes can execute bytecode directly through .pyc files, compiled-only modules, and marshalled code objects, creating an inspection-execution gap. We present an empirical study of Python bytecode as a security artifact. We measure bytecode exposure in PyPI...

Bai-Hong Chen, Tian Xie, Wen Li · 1 citation · ⚡1

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.