Documentation
/
VM Obfuscation
/

VM Self Defending

VM Self Defending

Pro
v6.2.0+

Watch

Obfuscator.io Advanced Defenses: Self-Defending, Debug Protection, Domain Lock

Watch on YouTube

The vmSelfDefending option adds multi-layered tamper detection, code integrity checks, anti-hooking, and anti-reverse-engineering protection to the VM runtime. When combined with vmDebugProtection, it makes both manual and AI-assisted analysis considerably harder.

This option force-enables vmBytecodeArrayEncoding and adds overhead to VM execution. Measure it on your own hot paths.

How each detection reacts - and how to report detections to your backend instead of only breaking - is covered in VM Defense Telemetry & Reactions; vmSelfDefending emits detections in the automation, debugger, tamper, and integrity reaction categories.

Recommended: Use together with vmDebugProtection, vmBytecodeArrayEncodingKey, and vmBytecodeArrayEncodingKeyGetter for maximum protection.

Runtime compatibility

Sensitive environment detection

This option binds the obfuscated code to its target runtime environment and uses advanced browser fingerprinting to detect automation tools. Code protected with this option will intentionally break when run in:

  • Headless browsers (headless Chrome/Chromium, PhantomJS)
  • Browser automation tools (Puppeteer, Playwright, Cypress, Selenium/ChromeDriver, Nightmare)
  • Node.js (when target is set to browser)
  • jsdom or similar server-side DOM emulations
  • Environments where native browser builtins have been hooked or replaced (unless declared with browserEnvironment.hookedBuiltins)

The code will work correctly in regular browsers (Chrome, Firefox, Safari, Edge), including when loaded inside iframes, browser extensions (content scripts), and Web Workers.

Choose the target for the actual runtime. Browser and Node builds contain different defenses: the node target omits the ones that rely on browser-only APIs, and a browser build run under Node breaks as listed above.

With browserEnvironment.hookedBuiltins set to true (v7.15.0+), Self Defending tolerates a runtime that legitimately replaces native builtins with JavaScript wrappers instead of treating them as tampering, so the protected code still runs there. This deliberately relaxes builtin-hook detection; the VM virtualization, anti-debugging, and integrity protections are unaffected. The same option's transport field binds the build to the scheme it is served over.

Self Defending checks the integrity of its own output, so do not minify, format, or otherwise rewrite the obfuscated code afterward. Run those tools on your source before the obfuscation step.

Testing and CI

These defenses also act against your own agents, automation, and debuggers. They may stop execution, throw unrelated errors, or produce incorrect results. This option is designed to prevent automated analysis and cannot be safely used with any automation framework, so run functional tests against a separate testing build with vmSelfDefending disabled. Testing and CI lists the full set of overrides for that build.