Need: Threat Detection & Prevention

Jscrambler 101 – Anti-Debugging

Welcome back to Jscrambler 101! A collection of tutorials on how to use Jscrambler to protect your JavaScript. This tutorial is about the Anti-Debugging transformation and covers Jscrambler version 8.3.

Introduction

We will explore Anti-Debugging, a new Jscrambler feature released in version 8.3. The Anti-Debugging feature protects your application by making it harder for attackers to debug an app by activating defenses that stop any reverse engineering attempts.

About Anti-Debugging

Before Anti-Debugging, Jscrambler offered an anti-debugging capability within the Self-Defending transformation. However, some concerns about more advanced reverse engineering and piracy ran deeper than this defense. Debugging with malicious intent, through, for example, bypassing the debugger with event listeners’ breakpoints, and then removing/disabling the fingerprinting or tampering with a license verification mechanism, was becoming a great concern. The Anti-Debugging feature was developed to make it increasingly harder for attackers to debug the code and commit fraud.

How does Anti-Debugging work?

This transformation uses several techniques to detect debugging activity. The user can define the countermeasures to be triggered if, during runtime, debugging activity is detected. When the code is protected with this transformation, checks are injected at the start of the program. Each check then runs three random techniques during runtime to detect debugging activity. Additionally, a different subset of techniques is used in each runtime to maximize the detection efficiency. Once detected, the countermeasures selected will be triggered.

Benefits of Anti-Debugging

With Anti-Debugging, there’s an opportunity to trust your environment more, making it easier to balance security and flexibility. It becomes increasingly more difficult for attackers to exploit dev tools designed to help your team debug to reverse engineer the code without being noticed. Key feature benefits include:
  • Enhanced detection – combining nine techniques heightens the ability to identify debugging activity. Each runtime uses a distinct subset of techniques, increasing the overall detection capabilities.
  • Stronger resilience – the injection of random checks in the source code reduces single points of failure, resulting in a more resilient defense against debugging activities.
  • Broader attack surface coverage – the diverse and independent nature of the techniques addresses various debugging approach strategies.
  • Extended defense protection – safeguarding against different types of breakpoints (conditional, exception, event, and XHR/fetch), offline debugging, and offering swift reactions upon detecting debugger activity.
  • Smooth and quick reaction – a wide array of countermeasures, such as custom callback, delete cookies, redirect, real-time notifications, data exfiltration prevention, self-destruct, and break application, provide an extensive defense toolkit. The option to stop or break application execution is discretionary.

Popular use cases

What are you protecting yourself against with Anti-Debugging? This is a great feature to shield from reverse engineering attempts that may have various forms of malicious intent:
  • Piracy
  • Licence abuse
  • Cheating and bypassing restrictions
 

Anti-Debugging

Self-Defending

FEATURES

Multiple Anti-Debugging Techniques YES NO
Detect Built-in Method Poisoning NO Limited
Stops the Event Loop NO YES
Anti-Debugging YES YES
Forces the Use of Anti-Debugging N/A YES
Allows breakpoint detection YES, if selected YES, always
Anti-Tampering NO YES
CSP: Requires unsafe-eval NO YES
Tolerate Minification YES Optional
Countermeasures: Disable Break Application YES NO
Countermeasures in General YES YES
Control with Annotations YES Limited

COMPATIBILITY

No Internet Needed YES YES
Modern Browsers YES YES
Internet Explorer NO/NOT TESTED YES
Node YES YES
React Native with Hermes YES NO
React Native YES YES
Other Mobile Frameworks YES YES

Conclusion

Anti-debugging is fully compatible with all major browsers and the browser’s Content-Security Policy (CSP), Node.js, and specific hybrid mobile frameworks, including Ionic, NativeScript, React Native, and React Native Hermes. Contrary to Anti-Tampering, it is possible to use both Self-Defending and Anti-Debugging, as the existing Self-Defending protection (against tampering and debugging) will remain available.  

Top European Airline Ensures Stellar Client-Side Protection with Jscrambler

Top European Airline Ensures Stellar Client-Side Protection with Jscrambler
Jscrambler’s advanced script and form security protection ensures sensitive form data is protected and malicious scripts cannot load.

Overview

This European airline is a global leader in air transportation that operates an extensive flight network connecting Europe to the world through its hubs in European capitals. With over 70,000 dedicated employees and a commitment to diversity, the airline serves millions of passengers across 300 destinations in 120 countries. A large portion of these passengers uses the company’s websites and mobile apps to book flights, check in online, chat with customer service, and redeem loyalty points.

Challenge

The client’s decision to search for client-side protection technology was initially triggered by a credit card data breach at another airline.

Before implementing Jscrambler, the client relied on more traditional security processes that involved checklists and paperwork. However, this manual approach left room for vulnerabilities: “We had security people who could decompile libraries, but they were usually too busy to do it.”.

When the client’s team needed to go fast and add new scripts, innovation sometimes took priority, which meant they would find workarounds to circumvent the documentation-heavy process, leaving them potentially open to attack.

Solution

In search of a comprehensive JavaScript monitoring and protection solution, the client considered various factors, including features and cost. Jscrambler stood out as the only solution that met their security requirements.

The client was particularly impressed by Jscrambler’s Form Fencing feature, which offers fine-grained behavioral control over third-party tag access to form data based on high-level assumptions and user-defined rules. Unlike other solutions, Jscrambler allowed the airline to authorize or block scripts individually.

The company put Jscrambler’s Webpage Integrity solution to the test in multiple Magecart attack scenarios. They ran dozens of tests to see if the solution could detect if content was added, modified, or removed from pages illicitly (DOM tampering), if form events were poisoned, or if data was exfiltrated to a drop server. Jscrambler’s technology passed every single test with flying colors and outperformed all the other available solutions. Adding Jscrambler to a page had little to no impact on its performance.

“Other solutions allow you to monitor cross-site scripting or visit CSP policies, but that’s all they do. They won’t protect forms. They won’t ask, “Is this sensitive data? Yes or no?” For us, Jscrambler was the best platform because they do it all.”
Information Analyst and Product Owner Mobile at Top European Airline

“With most companies, you buy a product, you get support for one or two months, and then you’re on your own. But with Jscrambler, we meet regularly twice a month. We know when new features are coming, even if they haven’t been released yet because they’ll tell us about them on our call and ask us what we think. It’s a nice dialogue to have. You really feel the personal touch. Jscrambler’s customer support is definitely a big plus.”
Information Analyst and Product Owner Mobile at Top European Airline

Top Jscrambler Features and Capabilities

  • Full Visibility and Control
  • Form Fencing
  • PCI DSS Compliance

Results

With zero security incidents, increased efficiency, and peace of mind, Jscrambler has become an integral part of the airline’s strategy for maintaining the highest security standards in today’s evolving digital landscape. The client attests, “We sleep easier at night because we know that the people at Jscrambler are looking out for us and our clients.”

Jscrambler WPI 101 – AI Assistant

For many, client-side security under PCI DSS v4 has evolved into a massive operational burden. With requirements 6.4.3 and 11.6.1 mandating the authorization and integrity of every script on payment pages, security analysts are drowning in a sea of script approvals. Jscrambler’s AI Assistant is designed to cut through this noise. Integrated directly into the Webpage Integrity (WPI) PCI DSS dashboard, it serves as an expert analyst, helping you validate the legitimacy of scripts running in payment pages, detect Magecart skimmers, and maintain PCI DSS v4 compliance with minimal effort and maximum confidence. This guide outlines the general workflow for using the AI Assistant: Reviewing Insights, Deep-Dive Investigation, and Taking Action.

Step 1: Access AI Insights

To get started, in your dashboard, navigate to Vendor Services in the PCI DSS dropdown. Here, you will see a list of all scripts running on your payment pages. Select the “needs review” filter to see every new script, or existing script that has changed its behavior, awaiting your review. To open up the AI insights panel, click on the vendor you would like to review, and the panel will open on the right-hand side.

Step 2: Initial Review with AI Insights & Recommendations

The Jscrambler AI Assistant performs a real-time analysis by cross-referencing detected behaviors, automated security evaluations, and known vendor purposes. The AI then determines if the script’s activity aligns with its stated function to provide tailored risk insights and recommendations. The AI flags any newly detected behaviors, such as accessing form data ( like payment information), connecting to external domains, or creating cross-origin iframes. It then performs security checks to determine whether this is legitimate script behavior or indicative of a threat, such as a web skimmer.
  • For Safe Behaviors: If the detected activity, such as network connections or iframe control, matches the known purpose of a vendor, the AI Assistant will recommend that you authorize and provide the specific permissions and actions that it should be allowed to perform.
  • For Abnormal Behaviors: If the script exhibits behaviors outside its expected purpose, such as an analytics tool suddenly accessing sensitive form data or transferring information to an unauthorized domain, it is flagged as a potential skimmer, and the AI will recommend blocking these specific behaviors immediately to mitigate the threat.

Step 3: Investigate Further with the AI Chat Assistant

If the initial insights are enough for you, you can finish the review and apply the recommended permissions to the vendor. But if you need more context before making a decision, click the Analyze with AI button. This opens a chat interface where you can query the AI assistant directly (using pre-built suggestions, or your own unique query) to validate your assumptions or scope a threat.

Validating Assumptions

For new vendors, you can ask general questions to confirm legitimacy:
  • “Tell me more about Stripe.”
  • “What additional risks are there with this script?”

Investigating Impact

For suspicious scripts, you can use the AI to understand the scope of an attack:
  • “How many customers might have been impacted by this malicious script?” (The AI can query session data to provide exact numbers, e.g., 10,000 sessions).
  • “What is the reputation of the target domains?” (The AI can identify unauthorized domains, confirming if data is being exfiltrated to a malicious URL).

Step 4: Remediation and Justification

The final stage of the workflow is taking action. The AI Assistant streamlines the compliance paperwork and technical configuration required for PCI DSS v4.

Automating Justification

When authorizing a vendor, the AI Assistant pre-populates the Justification field required for audits. It uses the insights gathered to write the note for you, ensuring consistent and accurate record-keeping. You remain in full control to edit this text or switch it off.

Applying Restrictions

When handling a threat, the Jscrambler AI Assistant can help you decide the correct granular permissions to set. Unlike other solutions that apply an all-or-nothing approach to blocking scripts (potentially breaking page functionality), you can follow the AI’s recommendation to block specific behaviors (such as network transfers or form data access) while leaving non-malicious script behaviors active that may be necessary for the page’s operation. Simply click Save to apply your decisions and complete the review.

Comply with Confidence

By following this workflow, you can use the Jscrambler AI to transform client-side security from a manual, error-prone task into a streamlined, data-driven process. The Jscrambler AI Assistant ensures that whether you are approving a new payment provider or mitigating an active skimmer, every decision is backed by expert intelligence.

Jscrambler WPI 101 – Getting Started

Web applications are facing growing threats from client-side attacks that seek to steal sensitive data and disrupt user experiences. Jscrambler’s Webpage Integrity (WPI) defends against these increasingly targeted risks by safeguarding web assets and payment pages against supply chain attacks, data exfiltration, DOM tampering, and more, while maintaining a seamless user experience and supporting compliance with data privacy-related regulations.

Understanding the Need for Webpage Integrity

With more websites relying on third-party scripts, the client-side attack surface has expanded significantly. Attackers exploit vulnerabilities in these scripts and forms to skim payment data, inject malicious code, or manipulate webpage behavior. Such attacks not only lead to financial losses but also cause critical damage to brand trust and compliance risks. Ensuring the integrity of every script running on the website is crucial for preventing data breaches and complying with regulations and standards, such as PCI DSS v4.

Key Features of Jscrambler Webpage Integrity

Jscrambler’s Webpage Integrity solution provides comprehensive capabilities designed to secure client-side environments:
  • Webpage Inventory: Automatically discover and monitor all third-party scripts (and all other scripts) present on the website, analyzing their origin, behavior, and prevalence to identify risk factors.

Inventory dashboard

  • Sensitive Data Overview: Get detailed reporting on events involving access to sensitive data on webpages (forms, cookies, browser storage, text elements), with filters to isolate alerts by vendor, page, or event type.
  • Form Fencing: Actively block unauthorized scripts from accessing form fields to prevent data skimming and leakage.
  • PCI DSS Compliance Module: Gain tools and reports to help meet PCI DSS version 4 requirements, particularly regarding script integrity on payment pages (6.4.3 and 11.6.1).

PCI DSS Vendor Services dashboard

  • Custom Policies: Define precise security rules without disrupting your user experience. Jscrambler’s customizable policies let you block, alert, or ignore specific script behaviors, such as unauthorized data access, directly on the client side. Instead of stopping scripts from running, WPI silently intercepts and neutralizes risky actions, preserving both page functionality and the integrity of sensitive data.
The Webpage Integrity product uses a hybrid architecture that combines Agent-Based Protection and Agentless Monitoring.  This flexibility lets organizations deploy rapid, lightweight monitoring on less critical pages while applying active, real-time blocking to high-risk areas such as login, payment, and other sensitive data entry forms. Data from both deployment types is integrated into a single unified dashboard, providing a seamless view of client-side risks and compliance status.

App Management dashboard

Step-by-Step Implementation Process

Integrating Jscrambler WPI follows a structured approach to ensure effective deployment and tuning:
  1. Kickoff & Team Alignment
To help things run as smoothly as possible, the Jscrambler team asks that you form a small cross-functional group on your side. Start by assigning the champion (e.g., someone with the title AppSec Lead, Architect, Security Manager, or Risk Manager) from your team for the duration of the integration process. That person will have regular meetings with the team and be the main point of contact. It is also essential to allocate some developer resources (DevOps) for the agent injection on the pages to be monitored in the beginning stage of the deployment. For PCI DSS compliance, it is recommended to loop in your Compliance/Fraud manager for alert triage.
  1. Planning and Scoping
After defining the WPI plan for the client, collaboration is key to identifying the websites and respective pages where the agent should be injected. During this phase, the sensitive forms to be monitored are also mapped, the customer’s first-party vendors are configured, and access permissions are set up for the group of users who will operate the dashboard.

Sensitive Data configurations

  1. Deployment
The successful deployment starts with injecting the Jscrambler agent into the web pages to be monitored, or with the Agentless monitoring component for those aiming to bring payment pages into compliance. Embedded Agent Injection The Jscrambler team shares the snippet instructions for injecting the Jscrambler agent. Usually, the DevOps from the customer side completes this action. The agent injection can be carried out in one of two ways: via code injection or via Tag Manager, in which case no development resources are needed. In an Agent-Based approach, the agent should be injected into previously configured websites and pages. It is recommended that the Jscrambler agent be one of the first scripts loaded on each page to ensure maximum visibility and control. This early injection provides stronger security coverage and ensures that monitoring and blocking can occur before any malicious scripts have a chance to execute. How the Jscrambler Agent Works The agent operates invisibly within end-users’ browsers to monitor script behavior, network requests, and DOM interactions. Importantly, all data transmitted to Jscrambler’s backend is anonymized to protect user privacy, with no personally identifiable information collected. This approach ensures near real-time visibility into any unauthorized or suspicious activity without compromising compliance. Best Practices for a Successful Implementation
  • Inject the agent as early as possible in the page load process to block threats before they can cause harm.
  • Appoint a dedicated project champion, such as a Security or Risk Manager, to coordinate communication and facilitate decision-making with Jscrambler’s team.
  • Use the initial configuration phase as an opportunity to continuously identify benign versus malicious actions in the environment, refining rules and alerts accordingly.
Agentless Monitoring allows WPI to run without any code changes or script deployments on the customer’s side. Instead of embedding an agent into live pages, Jscrambler uses a synthetic user that automatically visits the target pages and executes our data collection routines. This approach simulates real user behavior to detect and classify third-party scripts and potential skimming threats. The agentless option allows customers to move forward even when they can’t easily insert the agent into a web property, such as when they don’t have direct control over the application. To enable agentless monitoring on the web property, provide the Jscrambler team with the URLs of the properties and their corresponding payment pages you wish to monitor. Once the URLs are shared, the Jscrambler team will set up your account and provide the necessary login credentials for you and any additional users. Our team will also configure the websites and payment pages to be monitored by the Agentless Monitoring component.
  1. Configuration & Training
During the training period, insights gathered from the dashboard help confirm that the configured websites, pages, and other settings are correct or identify where small adjustments are needed. For use cases such as Form Fencing, control rules over sensitive forms should be validated to ensure they are properly defined and effective. Jscrambler’s team will be available throughout this process to assist with configuration review and verification. To ensure smooth configuration, weekly meetings can be held, and the topics discussed can include, but are not limited to:
  • Volume: Exact pages where the Jscrambler agent should work
  • Rules to alert about specific actions
  • New configuration requests
  • Custom events tracking
  1. Production
In the final stage, live threat monitoring and alerting begin, with ongoing adjustments to maximize security without impacting the user experience.
  1. Ongoing Operations, Support & Response
As a final step, an ongoing operating rhythm should be established to deliver long-term value from the platform. With the WPI dashboard, it is easy to do reviews, stay on top of the threats, automate compliance reporting, and stay audit-ready. Quarterly performance reviews with the Jscrambler Customer Success Manager can help optimize policies: analyzing blocked activity, updating allow-lists for new vendors, and refining rules as threats evolve. For incidents, rely on predefined rules to act quickly on alerts, including restricting access for suspicious scripts and escalating to Jscrambler support when needed.

Deployment Approaches: Agent-Based vs Agentless

  • Agent-Based Deployment: Embeds a hardened JavaScript agent directly within the website, enabling real-time detection and active blocking of malicious scripts. This method is preferred for high-risk pages needing comprehensive protection.
  • Agentless Monitoring: Not only applicable to this use case, but it also offers a faster path to PCI DSS compliance by passively scanning specified payment pages and tracking third-party services without impacting performance. It is ideal for initial rollouts or pages where direct agent insertion is not feasible.

Compliance and Security Confidence

Jscrambler’s infrastructure is PCI DSS-compliant, ISO 27001-certified, and GDPR-aligned. Regular internal and external penetration testing underpins the product’s security posture, providing customers with assessment-ready reports and increased assurance when protecting critical web applications.

Getting Started Tips

  • Get a full overview of all third-party vendors present on your website, and find out which teams, people, or processes can add JavaScript to the site. Is there a change management or approval process for this?
  • If you need to quickly gain visibility into web pages and third-party risks, start with Agentless Monitoring.
  • Share as many insights as possible during the configuration phase so that Jscrambler team can build tailored protections.
  • Leverage Jscrambler’s intuitive dashboards and real-time alerts to quickly respond to evolving threats.

Conclusion

Jscrambler’s WPI delivers essential, real-time protection against client-side threats that traditional security solutions often miss. Deploying WPI is a decisive step toward securing the client-side and future-proofing web applications against evolving attacks.  

Jscrambler 101 – Code Watermarking

Updated on July 15, 2025

Welcome back to Jscrambler 101! A collection of tutorials on how to use Jscrambler to protect your JavaScript. This tutorial covers the Code Watermarking feature, included in the Jscrambler version 8.5.


Introduction

In this article, we’ll explore Code Watermarking, a new Jscrambler feature released in version 8.5. Code Watermarking is a self-service feature that empowers customers to verify ownership of JavaScript code using robust, nearly unremovable watermarks, akin to a digital signature. This feature addresses intellectual property (IP) theft and supports forensic tracing for enterprises. 


About the Code Watermarking Protection Feature


How was the feature inspired?

The feature was created to address Jscrambler’s customers’ need for a self-service verification method. Many users are unaware of embedded watermarks, limiting their ability to address IP theft or investigate leaks in web applications. The feature focuses on self-service verification for JavaScript.


How does the Code Watermarking feature work?

The feature enables users to confirm JavaScript code ownership independently, leveraging watermarks’ signature-like persistence to protect frontend logic and trace code origins without manual support. The “Watermark” UI, as shown in the screenshot, provides an intuitive interface for watermark detection:


code-watermarketing-code-integrity-feature-explanation


It allows users to upload JavaScript files (.js, .mjs, .cjs formats) or input a URL. The system checks for robust, embedded watermarks (already included in protected code) and displays results: “Code belongs to [Organization], protected on [Date]” or “No watermark match found.” If the user disagrees with Jscrambler’s assessment that a piece of code is theirs, even if no watermark was found, they can submit the file for analysis by clicking a link that appears after our response. 


watermarking-detection-example

Code Watermarking Benefits 


  • Ownership Verification: confirms if suspect JavaScript is yours, akin to verifying a signature, streamlining IP dispute resolution.

  • IP Theft Deterrence: near-unremovable watermarks discourage copying by ensuring traceability, mirroring a signature’s trust signal.

  • Legal Evidence: provides signature-like proof of ownership for legal disputes.

  • Forensic Tracing: traces leaked JavaScript to its source, supporting breach investigations, similar to signatures that identify origins.

  • Increased Awareness: educate customers about watermarking’s signature-like capabilities.


Conclusion

Code Watermarking offers a robust, signature-like solution to verify JavaScript ownership. By enabling self-service verification within the organization, it delivers immediate value while laying the groundwork for future capabilities, such as automated code scanning, ownership certificates, and AI code attribution. This feature not only strengthens JavaScript security where traditional code signing falls short but also sets Jscrambler apart in a crowded market.

With ongoing customer feedback and planned integrations, Code Watermarking showcases the signature-like robustness of watermarks, emphasizing ownership verification, deterrence, and forensic tracing.