Announcing AfterPack: a free JavaScript obfuscator for the web A developer launched AfterPack, a free JavaScript obfuscator that reseeds every build so identifiers, encoded strings, decoder signatures and masked constants all change, aiming to break scripts written against a previous release. The developer reports that in a September 2026 measurement (six seeds × five samples), under 6% of what a deobfuscator recovered from one build still resolved on the next, and cites a May 2026 test in which Claude Opus 4.6 and 4.7 recovered clean source from two popular obfuscators' flagship demos in 10 and 20 minutes. The tool ships as a CLI, bundler plugins and a WebAssembly build for Cloudflare Workers, with Pro cloud builds starting at $49 a month. I built AfterPack; this is the launch post from our blog. Today we're launching three things: AfterPack afterpack.dev , the JavaScript obfuscator, works with any framework. The CLI and plugins are open source, the local engine is free, and Pro cloud builds start at $49 a month. Start with npx afterpack@latest after a build, or ask your coding agent to add it. Meet AfterPack: a free build tool that makes shipped code unreadable to scanners and people, and a moving target for AI. Every build ships completely different code, so a script written to patch one release — a cheat, a userscript, a bypass — doesn't fit the next. A tool written against your code should stop working at your next release, and now, inside your own Cloudflare Worker, it can stop working at your very next request. Because whatever AI can read, it can also rewrite and repackage. Point a coding agent at your bundle, and a few minutes later someone holds your pricing rules, your paywall check or your anti-bot logic as clean, editable source, along with a script that patches or bypasses them. That used to be a specialist's job; now it's a prompt. And the patch keeps working for as long as your code keeps its shape. Minification was never hiding that code: the Claude Code "leak" https://www.afterpack.dev/blog/claude-code-source-leak?utm source=devto&utm medium=social&utm campaign=launch was a readable bundle that had been sitting on npm since launch. What a minified bundle still gives away, and how to check your own site, is covered in what users can see in your JavaScript and how to protect it https://www.afterpack.dev/blog/protect-javascript-source-code?utm source=devto&utm medium=social&utm campaign=launch . In May 2026, I gave two popular obfuscators' own flagship demos to Claude Code with one four-paragraph prompt. Claude Opus 4.6 came back with clean source https://www.afterpack.dev/blog/ai-deobfuscates-javascript?utm source=devto&utm medium=social&utm campaign=launch in 10 minutes, Claude Opus 4.7 in 20. They were small demos, not whole apps, and those models are already a generation behind today's. Your pricing rules, license checks, anti-fraud heuristics and unreleased features have always been in the bundle. What changed is who can read them, and how fast. What you still control is how much of that work carries over to your next release. Yes. Given enough time, any obfuscator's output can be reversed, AfterPack's included. What AfterPack changes is carry-over: how much of the work to reverse one release still applies to the next. In our own measurement September 2026, six seeds × five samples , under 6% of what a deobfuscator recovered from one build still resolved on the next how we measured https://www.afterpack.dev/docs/comparison?utm source=devto&utm medium=social&utm campaign=launch how-we-measured . Logic someone has already read also stays read: if they worked out your discount rule once, a new build won't make them forget it. What can expire is the tool built on that read. A script that strips a license check, a patcher for a paywall, an extractor that pulls your scoring rules out of every release: each is written against the structure of one build. The most popular open-source obfuscator emits fixed output shapes, and free public deobfuscators ship hardcoded recognizers for them, so a tool written once keeps working on every future build. AfterPack starts from a new random seed on every build. Identifier names, encoded strings, the decoder's signature, state numbering and masked constants all come out different, so the details a tool hard-codes change every time. Run the engine inside a Worker and the window shrinks from a release to a single request. A CLI, plugins for the bundlers you already use, a WebAssembly build for Workers, Pro cloud builds, a report of what each build protected, and a free site scanner. | Fact | AfterPack | |---|---| | What it is | A JavaScript obfuscator for production builds: it rewrites what your bundler produces, not your source files | | Engine | Rust, run locally by the CLI and the plugins, or as WebAssembly @afterpack/wasm https://www.afterpack.dev/docs/workers?utm source=devto&utm medium=social&utm campaign=launch inside your own Worker | | Output | Different on every build by default in the CLI and the plugins; pin a seed https://www.afterpack.dev/docs/builds?utm source=devto&utm medium=social&utm campaign=launch only when you need identical bytes | | License | CLI and plugins Apache-2.0; the engine is free to use under the AfterPack Engine License | | Price | Local engine free; Pro from $49 a month plans https://www.afterpack.dev/docs/tiers?utm source=devto&utm medium=social&utm campaign=launch | | Start | npx afterpack@latest after your build, or a framework plugin https://www.afterpack.dev/docs/frameworks?utm source=devto&utm medium=social&utm campaign=launch | What the table doesn't show: npx afterpack audit