Wobfuscator: Obfuscating JavaScript Malware via Opportunistic Translation to WebAssembly
Alan Romano, Daniel Lehmann, Michael Pradel, Weihang Wang
Abstract
To protect web users from malicious JavaScript code, various malware detectors have been proposed, which analyze and classify code as malicious or benign. State-of-the-art detectors focus on JavaScript as the only target language. However, WebAssembly provides attackers a new and so far unexplored opportunity for evading malware detectors. This paper presents Wobfuscator, the first technique for evading static JavaScript malware detection by moving parts of the computation into WebAssembly. The core of the technique is a set of code transformations that translate carefully selected parts of behavior implemented in JavaScript into WebAssembly. The approach is opportunistic in the sense that it uses WebAssembly where it helps to evade malware detection without compromising the correctness of the code. Evaluating our approach with a dataset of 43,499 malicious and 149,677 benign JavaScript files, as well as six popular JavaScript libraries reveals that our approach is effective at evading state-of-the-art, learning-based static malware detectors; the obfuscation is semantic-preserving; and our approach has small overhead, making it practical for use in real-world programs. By pinpointing limitations of current malware detectors, our work motivates future efforts on detecting multi-language malware in the web.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e22770bf-91d9-43b6-81b3-dbfd0d050566Cited by top-tier papers14
- Large Language Models for Code Analysis: Do LLMs Really Do Their Job?Chongzhou Fang, Ning Miao, Shaurya Srivastav, Jialin Liu et al.USENIX Security 2024 · 110 citations
- Finding the dwarf: recovering precise types from WebAssembly binariesDaniel Lehmann, Michael PradelPLDI 2022 · 29 citations
- That's a Tough Call: Studying the Challenges of Call Graph Construction for WebAssemblyDaniel Lehmann, Michelle Thalakottur, Frank Tip, Michael PradelISSTA 2023 · 11 citations
- An Empirical Study on the Effects of Obfuscation on Static Machine Learning-Based Malicious JavaScript DetectorsKunlun Ren, Weizhong Qiang, Yueming Wu, Yi Zhou et al.ISSTA 2023 · 11 citations
- Wasm-R3: Record-Reduce-Replay for Realistic and Standalone WebAssembly BenchmarksDoehyun Baek, Jakob Getz, Yusung Sim, Daniel Lehmann et al.OOPSLA 2024 · 6 citations
Builds on7
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- MineSweeper: An In-depth Look into Drive-by Cryptocurrency Mining and Its DefenseRadhesh Krishnan Konoth, Emanuele Vineti, Veelasha Moonsamy, Martina Lindorfer et al.CCS 2018 · 162 citations
- How You Get Shot in the Back: A Systematical Study about Cryptojacking in the Real WorldGeng Hong, Zhemin Yang, Sen Yang, Lei Zhang et al.CCS 2018 · 120 citations
- An Empirical Study of Real-World WebAssembly Binaries: Security, Languages, Use CasesAaron Hilbig, Daniel Lehmann, Michael PradelWWW 2021 · 114 citations
- HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTsAurore Fass, Michael Backes, Ben StockCCS 2019 · 78 citations
Related papers
- WasmGuard: Enhancing Web Security through Robust Raw-Binary Detection of WebAssembly MalwareYuxia Sun, Huihong Chen, Zhixiao Fu, Wenjian Lv et al.WWW 2025 · 2 citations
- An Empirical Study of WebAssembly Usage in Node.jsMichelle Thalakottur, Maxwell Bernstein, Daniel Lehmann, Michael Pradel et al.ICSE 2026
- Everything Old is New Again: Binary Security of WebAssemblyDaniel Lehmann, Johannes Kinder, Michael PradelUSENIX Security 2020
- An Empirical Study of Bugs in WebAssembly CompilersAlan Romano, Xinyue Liu, Yonghwi Kwon, Weihang WangASE 2021 · 43 citations
- WAMO: Toward Secure Browser Inference via Web Model Obfuscation in WebAssemblyYitong Wang, Pengfei Yu, Hao Han, Jingjing Gu et al.WWW 2026
