VM Self Defending
Watch
Obfuscator.io Advanced Defenses: Self-Defending, Debug Protection, Domain Lock
The vmSelfDefending option adds multi-layered tamper detection, code integrity checks, anti-hooking, and anti-reverse-engineering protection to the VM runtime. When combined with vmDebugProtection, it makes both manual and AI-assisted analysis considerably harder.
This option force-enables vmBytecodeArrayEncoding and adds overhead to VM execution. Measure it on your own hot paths.
How each detection reacts - and how to report detections to your backend instead of only breaking - is covered in VM Defense Telemetry & Reactions; vmSelfDefending emits detections in the automation, debugger, tamper, and integrity reaction categories.
Recommended: Use together with vmDebugProtection, vmBytecodeArrayEncodingKey, and vmBytecodeArrayEncodingKeyGetter for maximum protection.
Runtime compatibility
Sensitive environment detection
This option binds the obfuscated code to its target runtime environment and uses advanced browser fingerprinting to detect automation tools. Code protected with this option will intentionally break when run in:
- Headless browsers (headless Chrome/Chromium, PhantomJS)
- Browser automation tools (Puppeteer, Playwright, Cypress, Selenium/ChromeDriver, Nightmare)
- Node.js (when
targetis set tobrowser) - jsdom or similar server-side DOM emulations
- Environments where native browser builtins have been hooked or replaced (unless declared with
browserEnvironment.hookedBuiltins)
The code will work correctly in regular browsers (Chrome, Firefox, Safari, Edge), including when loaded inside iframes, browser extensions (content scripts), and Web Workers.
Choose the target for the actual runtime. Browser and Node builds contain different defenses: the node target omits the ones that rely on browser-only APIs, and a browser build run under Node breaks as listed above.
With browserEnvironment.hookedBuiltins set to true (v7.15.0+), Self Defending tolerates a runtime that legitimately replaces native builtins with JavaScript wrappers instead of treating them as tampering, so the protected code still runs there. This deliberately relaxes builtin-hook detection; the VM virtualization, anti-debugging, and integrity protections are unaffected. The same option's transport field binds the build to the scheme it is served over.
Self Defending checks the integrity of its own output, so do not minify, format, or otherwise rewrite the obfuscated code afterward. Run those tools on your source before the obfuscation step.
Testing and CI
These defenses also act against your own agents, automation, and debuggers. They may stop execution, throw unrelated errors, or produce incorrect results. This option is designed to prevent automated analysis and cannot be safely used with any automation framework, so run functional tests against a separate testing build with vmSelfDefending disabled. Testing and CI lists the full set of overrides for that build.
