Need: Client-Side Security

Jscrambler 101 – Anti-Debugging

Welcome back to Jscrambler 101! A collection of tutorials on how to use Jscrambler to protect your JavaScript. This tutorial is about the Anti-Debugging transformation and covers Jscrambler version 8.3.

Introduction

We will explore Anti-Debugging, a new Jscrambler feature released in version 8.3. The Anti-Debugging feature protects your application by making it harder for attackers to debug an app by activating defenses that stop any reverse engineering attempts.

About Anti-Debugging

Before Anti-Debugging, Jscrambler offered an anti-debugging capability within the Self-Defending transformation. However, some concerns about more advanced reverse engineering and piracy ran deeper than this defense. Debugging with malicious intent, through, for example, bypassing the debugger with event listeners’ breakpoints, and then removing/disabling the fingerprinting or tampering with a license verification mechanism, was becoming a great concern. The Anti-Debugging feature was developed to make it increasingly harder for attackers to debug the code and commit fraud.

How does Anti-Debugging work?

This transformation uses several techniques to detect debugging activity. The user can define the countermeasures to be triggered if, during runtime, debugging activity is detected. When the code is protected with this transformation, checks are injected at the start of the program. Each check then runs three random techniques during runtime to detect debugging activity. Additionally, a different subset of techniques is used in each runtime to maximize the detection efficiency. Once detected, the countermeasures selected will be triggered.

Benefits of Anti-Debugging

With Anti-Debugging, there’s an opportunity to trust your environment more, making it easier to balance security and flexibility. It becomes increasingly more difficult for attackers to exploit dev tools designed to help your team debug to reverse engineer the code without being noticed. Key feature benefits include:
  • Enhanced detection – combining nine techniques heightens the ability to identify debugging activity. Each runtime uses a distinct subset of techniques, increasing the overall detection capabilities.
  • Stronger resilience – the injection of random checks in the source code reduces single points of failure, resulting in a more resilient defense against debugging activities.
  • Broader attack surface coverage – the diverse and independent nature of the techniques addresses various debugging approach strategies.
  • Extended defense protection – safeguarding against different types of breakpoints (conditional, exception, event, and XHR/fetch), offline debugging, and offering swift reactions upon detecting debugger activity.
  • Smooth and quick reaction – a wide array of countermeasures, such as custom callback, delete cookies, redirect, real-time notifications, data exfiltration prevention, self-destruct, and break application, provide an extensive defense toolkit. The option to stop or break application execution is discretionary.

Popular use cases

What are you protecting yourself against with Anti-Debugging? This is a great feature to shield from reverse engineering attempts that may have various forms of malicious intent:
  • Piracy
  • Licence abuse
  • Cheating and bypassing restrictions
 

Anti-Debugging

Self-Defending

FEATURES

Multiple Anti-Debugging Techniques YES NO
Detect Built-in Method Poisoning NO Limited
Stops the Event Loop NO YES
Anti-Debugging YES YES
Forces the Use of Anti-Debugging N/A YES
Allows breakpoint detection YES, if selected YES, always
Anti-Tampering NO YES
CSP: Requires unsafe-eval NO YES
Tolerate Minification YES Optional
Countermeasures: Disable Break Application YES NO
Countermeasures in General YES YES
Control with Annotations YES Limited

COMPATIBILITY

No Internet Needed YES YES
Modern Browsers YES YES
Internet Explorer NO/NOT TESTED YES
Node YES YES
React Native with Hermes YES NO
React Native YES YES
Other Mobile Frameworks YES YES

Conclusion

Anti-debugging is fully compatible with all major browsers and the browser’s Content-Security Policy (CSP), Node.js, and specific hybrid mobile frameworks, including Ionic, NativeScript, React Native, and React Native Hermes. Contrary to Anti-Tampering, it is possible to use both Self-Defending and Anti-Debugging, as the existing Self-Defending protection (against tampering and debugging) will remain available.  

Marriott Vacations Worldwide Secures the Browser with Jscrambler

Marriott Vacations Worldwide Secures the Browser with Jscrambler
Marriott Vacations Worldwide (MVW) enhances visibility and control over its client-side environment after meeting the PCI DSS requirements 6.4.3 and 11.6.1 with Jscrambler’s Webpage Integrity (WPI).

Overview

Marriott Vacations Worldwide is a global vacation company that offers vacation ownership, exchange, rental, and resort and property management, along with related businesses, products, and services. The company has a diverse portfolio that includes seven vacation ownership brands. It also includes exchange networks and membership programs, as well as management of other resorts and lodging properties.

Challenge

As a large, digitally driven organization operating in a highly regulated environment, Marriott Vacations Worldwide faces increasing pressure to protect customer data, especially credit card data, across complex web environments, particularly in the browser. Like many enterprise organizations, MVW relies on numerous third-party scripts and marketing tags to deliver personalized experiences and optimize performance. However, this growing client-side ecosystem introduces visibility and control challenges, such as shadow IT and unvetted third-party vendor scripts introduced by marketing and sales teams.

The scale of the scope challenge to discover all the payment pages became especially clear during their internal discovery work: “We did a complete inventory of our web-based payment pages that accept credit cards. That was not an easy task to accomplish. Full disclosure, it took 9 months here for us to discover every single web-based page where we accept credit cards. That kind of just talks to the complexity of the organization.” The core challenge wasn’t simply tracking scripts; it was maintaining continuous visibility and control across a large, evolving digital footprint with a small team managing compliance for multiple entities simultaneously.

Solution

The MVW team was aware of PCI DSS requirements 6.4.3 and 11.6.1 early on and used the on-ramp period to identify a solution. MVW’s websites are highly dynamic, with marketing sites frequently updated, and marketing and sales teams often perform site refreshes outside of IT. The team needed a solution that directly met 6.4.3 and 11.6.1, which ruled out options like a CDN or a combination of CSP and SRI due to the required learning curve and manual effort. After evaluating various approaches, MVW selected Jscrambler’s Webpage Integrity (WPI) product to meet the requirements 6.4.3 and 11.6.1 and improve third-party script control in its browser environment.

By automating client-side monitoring, the solution eliminated the need for manual oversight and significantly reduced operational burden. Its seamless integration with the SIEM provided effective visibility without generating excessive alerts. The intuitive UI also made it easy to manage approvals and push business justifications directly to stakeholders, streamlining governance across teams. TJ mentioned that the solution included what he called a “panic button” feature that allows certain third-party scripts to be instantly cut off from data access without impacting performance. Essentially, the Jscrambler platform provides granular control over third-party scripts, enabling MVW to restrict access to sensitive data while still allowing third-party services to function as intended.

TJ noted that, given the organization’s complexity, the journey was not easy. However, the Jscrambler team made the whole process smooth and pain-free: “Early on, it was a pleasure to work with Jscrambler. Jscrambler really stepped up for us. We have more than 15 unique codebases. It was difficult, but it worked out well for us.”

“We haven’t found anything else out there in the market today that provides all of the benefits from the length of time Jscrambler’s been at this to the ease of use of this solution, and directly meeting the PCI requirements.”
TJ Goldsmith

PCI Compliance Program Director at Marriott Vacations Worldwide

Top Jscrambler Features and Capabilities

  • Granular control over third-party scripts
  • Intuitive UI and minimal learning curve
  • Low-noise alerting

Results

Marriott Vacations Worldwide achieved full compliance with PCI DSS v4 requirements 6.4.3 and 11.6.1 ahead of the enforcement deadline. As TJ shared, “We were 100% compliant before we needed to be.”

By implementing Jscrambler, Marriott Vacations Worldwide achieved:

  • Evidence of Compliance
    Compliance with PCI DSS 6.4.3 & 11.6.1, ease of demonstrating/providing evidence of compliance
  • Visibility & Control
    Enhanced visibility & control over all payment pages across all brands
  • Full Client-Side Protection
    Platform leveraged by other internal teams outside of PCI Compliance
  • Improved Risk Posture
    Improved risk posture through real-time script monitoring and header integrity validation

For Marriott Vacations Worldwide, client-side protection was not simply about checking a compliance box. It was about protecting 160 card data flows across six distinct entities, managing dynamic marketing environments, reducing operational burden, and preserving brand trust. With Jscrambler, MVW implemented a solution that did all that while keeping a lean compliance team efficient.

Top European Airline Ensures Stellar Client-Side Protection with Jscrambler

Top European Airline Ensures Stellar Client-Side Protection with Jscrambler
Jscrambler’s advanced script and form security protection ensures sensitive form data is protected and malicious scripts cannot load.

Overview

This European airline is a global leader in air transportation that operates an extensive flight network connecting Europe to the world through its hubs in European capitals. With over 70,000 dedicated employees and a commitment to diversity, the airline serves millions of passengers across 300 destinations in 120 countries. A large portion of these passengers uses the company’s websites and mobile apps to book flights, check in online, chat with customer service, and redeem loyalty points.

Challenge

The client’s decision to search for client-side protection technology was initially triggered by a credit card data breach at another airline.

Before implementing Jscrambler, the client relied on more traditional security processes that involved checklists and paperwork. However, this manual approach left room for vulnerabilities: “We had security people who could decompile libraries, but they were usually too busy to do it.”.

When the client’s team needed to go fast and add new scripts, innovation sometimes took priority, which meant they would find workarounds to circumvent the documentation-heavy process, leaving them potentially open to attack.

Solution

In search of a comprehensive JavaScript monitoring and protection solution, the client considered various factors, including features and cost. Jscrambler stood out as the only solution that met their security requirements.

The client was particularly impressed by Jscrambler’s Form Fencing feature, which offers fine-grained behavioral control over third-party tag access to form data based on high-level assumptions and user-defined rules. Unlike other solutions, Jscrambler allowed the airline to authorize or block scripts individually.

The company put Jscrambler’s Webpage Integrity solution to the test in multiple Magecart attack scenarios. They ran dozens of tests to see if the solution could detect if content was added, modified, or removed from pages illicitly (DOM tampering), if form events were poisoned, or if data was exfiltrated to a drop server. Jscrambler’s technology passed every single test with flying colors and outperformed all the other available solutions. Adding Jscrambler to a page had little to no impact on its performance.

“Other solutions allow you to monitor cross-site scripting or visit CSP policies, but that’s all they do. They won’t protect forms. They won’t ask, “Is this sensitive data? Yes or no?” For us, Jscrambler was the best platform because they do it all.”
Information Analyst and Product Owner Mobile at Top European Airline

“With most companies, you buy a product, you get support for one or two months, and then you’re on your own. But with Jscrambler, we meet regularly twice a month. We know when new features are coming, even if they haven’t been released yet because they’ll tell us about them on our call and ask us what we think. It’s a nice dialogue to have. You really feel the personal touch. Jscrambler’s customer support is definitely a big plus.”
Information Analyst and Product Owner Mobile at Top European Airline

Top Jscrambler Features and Capabilities

  • Full Visibility and Control
  • Form Fencing
  • PCI DSS Compliance

Results

With zero security incidents, increased efficiency, and peace of mind, Jscrambler has become an integral part of the airline’s strategy for maintaining the highest security standards in today’s evolving digital landscape. The client attests, “We sleep easier at night because we know that the people at Jscrambler are looking out for us and our clients.”